Impact
A vulnerable implementation of the Anonymize Links plugin permits attackers to exploit a CSRF flaw that injects arbitrary script code into the site database. When an authenticated administrator or editor makes a crafted request, the malicious payload is stored and then rendered on subsequent page loads. An attacker who gets the script executed in a victim’s browser may steal cookies, hijack sessions, or perform further malicious actions. The weakness is a Cross‑Site Request Forgery that leads to persistent client‑side script execution, as identified by CWE‑352.
Affected Systems
The flaw affects the Schalk Burger Anonymize Links WordPress plugin version 1.1 and earlier. Users who are running any version from the product’s release history through 1.1 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. Based on the description, the attack requires a logged‑in user to submit a crafted request that embeds malicious script, implying that social engineering such as a deceptive email or malicious link directed at administrators or editors is likely the method the attacker would use to obtain the necessary credentials.
OpenCVE Enrichment
EUVD