Impact
A Cross‑Site Request Forgery flaw in Tussendoor B.V.’s Call me Now WordPress plugin allows an attacker to submit a forged request that stores malicious script data. The stored payload is later served to site visitors, enabling execution of arbitrary JavaScript in the context of the victim’s browser. This bypasses Same‑Origin protections, potentially exposing users to phishing, credential theft, and other client‑side attacks.
Affected Systems
Any WordPress site that has the Call me Now plugin installed with a version equal to or older than 1.0.5 is affected. The vulnerability applies to all installations that rely on the default configuration of the plugin, as the CSRF check is missing for the relevant stored‑content operation.
Risk and Exploitability
The CVSS score of 7.1 reflects a high impact combined with the requirement for an authenticated user to perform the action. The EPSS score of less than 1% indicates a low probability of public exploitation at this time, and the vulnerability is not yet listed in CISA’s KEV catalog. An attacker would create a malicious link or form that an authenticated user unknowingly submits; the plugin then stores the attacker’s script, which is rendered to any site visitor. Because the flaw is dependent on the attacker forming a valid request, manual intervention or user action is the primary prerequisite for exploitation.
OpenCVE Enrichment
EUVD