Impact
Cross‑site request forgery in the RaymondDesign Post & Page Notes plugin allows an attacker to have a logged‑in user unknowingly save a note that contains malicious script. Because the plugin accepts the note content without validating the request origin or sanitizing the input, the embedded script is stored and later rendered unfiltered. When any WordPress visitor opens the note, the script executes in the visitor’s browser, providing a stored XSS vector that can be used to run arbitrary code within the user’s session context.
Affected Systems
WordPress installations that use the RaymondDesign Post & Page Notes plugin at version 0.1.1 or earlier are affected. All releases prior to and including that version contain the flaw, as the vendor’s notice indicates the vulnerability exists in every version up to 0.1.1.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high risk to confidentiality, integrity, and availability. The EPSS score is below 1 % and the issue is not listed in the CISA KEV catalog. An attacker can craft a CSRF request that forces an authenticated user to save a tainted note; the stored, unsanitized content is then rendered when the note is viewed, providing a clear and straightforward exploitation path.
OpenCVE Enrichment
EUVD