Impact
This vulnerability exposes a Cross‑Site Request Forgery flaw that allows an attacker to store malicious script code in the WordPress MFPlugin. Once the script is stored and later rendered by the site, it can harvest user data, hijack sessions, or deface the website. The weakness is a classic CSRF that facilitates a stored XSS attack (CWE‑352).
Affected Systems
The flaw affects the waltercerrudo MFPlugin from the earliest available version through 1.3 inclusive. Users running any intact installation of that plugin without a newer release are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity level. The EPSS score of less than 1% suggests that the probability of exploitation in the wild is currently very low, and the vulnerability is not listed in the CISA KEV catalog. Still, the compromise could occur if an attacker can submit a forged request while the victim is authenticated, which is the anticipated attack vector inferred from the CSRF nature of the issue.
OpenCVE Enrichment
EUVD