Impact
The vulnerability is a CSRF flaw that enables an attacker to store malicious JavaScript payloads in the MercadoLibre Integration plugin. When an authenticated user submits a forged request, the plugin records the payload. On subsequent visits to the relevant page the stored script executes in the victim’s browser, allowing data theft, session hijacking or defacement. The flaw is a cross‑site request forgery that results in stored XSS, classified as CWE‑352.
Affected Systems
Any WordPress site running the MercadoLibre Integration plugin version 1.1 or earlier is affected. The vendor listed is hernanjh. The issue resides solely in the WordPress plugin code and is independent of the underlying operating system.
Risk and Exploitability
The CVSS base score is 7.1, indicating moderate‑to‑high severity, but the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV database. Exploitation requires a legitimate user be tricked into submitting a forged request, so an attacker needs access to a user account capable of performing the vulnerable action. Once the payload is stored, all users who view the affected page are impacted, making the potential damage broad. Despite the low exploitation probability, the widespread cross‑site scripting risk warrants immediate remediation.
OpenCVE Enrichment
EUVD