Impact
The vulnerability allows an attacker to send a forged request that causes the WordPress mybb Last Topics plugin to store malicious script data in the database. When other site visitors load a topic list, the stored script is executed in their browsers, enabling client‑side code execution that can compromise session integrity, steal authentication cookies, or perform phishing and defacement. This reflects a Stored Cross‑Site Scripting (Stored XSS) weakness amplified by a Cross‑Site Request Forgery (CSRF) vector.
Affected Systems
WordPress installations using the progpars.net mybb Last Topics plugin version 1.0 or earlier are affected. The plugin is bundled as a WordPress plugin and can be used on any site that has installed it.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The issue is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector requires an authenticated user to be tricked into submitting a forged request, meaning that an attacker must first compromise or masquerade a legitimate site user before the stored XSS payload can be injected.
OpenCVE Enrichment
EUVD