Impact
WordPress Twitter Post plugin version 0.1 or earlier contains a Cross‑Site Request Forgery (CSRF) flaw that allows malicious code to be stored and later executed when visitors view affected content, resulting in stored cross‑site scripting (XSS). The CVE description does not specify whether the attack requires an authenticated user; that detail is inferred from typical CSRF mechanisms but is not confirmed by the official record.
Affected Systems
Any WordPress site that has the krolow Twitter Post plugin installed at version 0.1 or earlier is affected. No other vendor products or newer plugin versions are listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity impact once the flaw is used successfully. The EPSS score of less than 1% suggests that real‑world exploitation is currently uncommon, and the vulnerability does not appear in the CISA KEV catalog. The flaw permits the storage of malicious scripts that are executed when site visitors view the affected content.
OpenCVE Enrichment
EUVD