Impact
This flaw permits an attacker to perform a Cross‑Site Request Forgery exploit that stores malicious JavaScript within the DF Draggable plugin. Once stored, the script runs automatically in the browsers of any user who views content processed by the plugin, allowing arbitrary client‑side code execution.
Affected Systems
All releases of the DF Draggable WordPress plugin up to and including version 1.13.2 are affected. Any installation using a version numbered 1.13.2 or earlier remains vulnerable unless updated to a newer release.
Risk and Exploitability
The vulnerability receives a CVSS score of 7.1, an EPSS score of less than 1%, and is not listed in the CISA KEV catalog. While the description does not specify whether authentication is required, based on the nature of CSRF attacks it is inferred that a user with site access—for example, a logged‑in contributor or administrator—could be tricked into submitting a forged request that injects the payload. The stored nature of the flaw means the malicious code persists across sessions and affects all users who view the compromised content.
OpenCVE Enrichment
EUVD