Impact
This vulnerability allows an attacker to perform a cross‑site request forgery that results in arbitrary data being stored in the WordPress site. When a victim later views the stored content, the malicious script can execute in the victim’s browser, potentially leaking credentials, defacing the site, or hijacking the user’s session. The weakness is a classic Stored XSS, listed as CWE‑352, and can compromise confidentiality and integrity for end‑users.
Affected Systems
The flaw affects the ArtkanMedia Book a Place plugin for WordPress versions from the initial release through 0.7.1. Any WordPress installation that has this version of the plugin installed is at risk.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity; however the EPSS score of less than 1% indicates a low probability of observed exploitation. The flaw is not currently cataloged in CISA’s KEV database. The likely attack vector is a CSRF exploit that requires the victim to be authenticated to the WordPress site, so the attacker would use a malicious link or form to trigger the stored XSS payload. Because the payload is persisted, any user who has read access to the stored data could be impacted.
OpenCVE Enrichment
EUVD