Impact
The CVE describes a Cross‑Site Request Forgery flaw that allows an attacker to store malicious JavaScript in the Shabbos and Yom Tov plugin. By tricking an authenticated administrator into sending a crafted request, the attacker can inject a payload that is later rendered when any site visitor loads the affected page. This Stored XSS can lead to session hijacking, credential theft, or defacement of the website.
Affected Systems
The vulnerability affects the WordPress plugin Shabbos and Yom Tov produced by shabboscommerce. All releases up to and including version 1.9 are impacted. No specific version higher than 1.9 is listed as vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high severity. The EPSS score is under 1 percent, suggesting a low probability of exploitation at present, and it is not listed in the CISA KEV catalog. The exploit requires that the attacker be able to coerce a logged‑in administrator into submitting a forged request, so authenticated users or users with administrative privileges are the primary target. If an attacker succeeds, the stored script executes in the context of any user who views the affected page, potentially compromising confidentiality, integrity, and availability of the site.
OpenCVE Enrichment
EUVD