Impact
Cross‑Site Request Forgery in the Braulio Aquino Send to Twitter plugin allows an attacker to inject arbitrary script into stored data. When an authenticated visitor submits a forged request, malicious code is stored and later executed in the browsing context of other users, leading to stored cross‑site script exploitation. This weakness is categorized as CWE‑352.
Affected Systems
Braulio Aquino’s Send to Twitter WordPress plugin, all releases up to and including version 1.7.2, is affected. Users should check that they are running the latest available version or have removed the plugin if it is unnecessary.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1 % suggests a low but non‑zero probability of exploitation. The vulnerability has not been listed in CISA’s KEV catalog. Attackers can exploit it through a CSRF vector that requires a victim to be logged into the WordPress site; the resulting stored code can be executed whenever the affected content is rendered.
OpenCVE Enrichment
EUVD