Impact
Cross‑Site Request Forgery allows a threat actor to force a logged‑in WordPress user to submit a request to the Auphonic Importer plugin that stores malicious JavaScript. Once stored, the script runs for every user who views the affected content, potentially enabling credential theft, defacement, or other malicious actions. The weakness stems from the plugin’s failure to implement a verification token (nonce) on state‑changing requests.
Affected Systems
Kreg Steppe Auphonic Importer plugin, versions up to and including 1.5.1. WordPress sites running any of these plugin versions are vulnerable; no specific WordPress core versions are listed.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity vulnerability. The EPSS score of less than 1% suggests exploitation is unlikely in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by exploiting the lack of CSRF protection: a malicious webpage can load an authenticated request into a logged‑in user’s session, which stores the payload on the server. While this does not provide remote code execution, the stored script can compromise the confidentiality and integrity of site content for all visitors.
OpenCVE Enrichment
EUVD