Impact
This vulnerability arises from a Cross‑Site Request Forgery flaw that allows an attacker to inject malicious scripts that are stored in the WordPress database. Once stored, these scripts execute whenever a page is rendered, compromising the integrity and confidentiality of the site and potentially exposing end‑user data. The vulnerability can lead to credential theft, session hijacking, or further exploitation of the WordPress installation.
Affected Systems
The WP Panoramio plugin from the ryscript vendor, all releases up to and including version 1.5.0, are affected. The issue lists coverage from the initial release through <=1.5.0 with no earlier baseline specified.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as medium‑high severity. The EPSS score is below 1%, indicating a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a CSRF attack that requires a user interacting with a crafted link or form; because the payload is stored, no immediate user interaction after injection is required for the XSS to execute on other visitors.
OpenCVE Enrichment
EUVD