Impact
The vulnerability is a Cross‑Site Request Forgery that allows malicious JavaScript to be injected and stored within the plugin’s data. Because the script is persisted, it executes whenever the affected content is viewed by any user. Based on the nature of stored XSS, this could lead to data theft, defacement, or session hijacking, although the CVE text does not explicitly confirm these outcomes.
Affected Systems
The affected product is the Flying Twitter Birds WordPress plugin version 1.8 or earlier, published by Mayur Sojitra. WordPress sites that have this plugin installed are vulnerable to the issue.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity, while the EPSS score of less than 1% points to a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalogue, suggesting no known active exploitation campaigns. Because the flaw is described as a CSRF vulnerability, exploitation generally requires forging a request from a logged‑in user or using social engineering to get a user to submit a malicious request.
OpenCVE Enrichment
EUVD