Impact
The OrangeBox plugin for WordPress, supplied by nova706, contains a CSRF flaw that can allow an attacker to forge a request which stores a malicious script in the plugin’s data. Once stored, the script can be executed in the browsers of any visitor who later loads the affected content, resulting in a persistent cross‑site scripting vulnerability. This weakness is categorized under CWE-352.
Affected Systems
The vulnerability affects the OrangeBox plugin version 3.0.0 and any earlier releases. Any WordPress site that has a vulnerable instance of the plugin installed is at risk, regardless of the WP version.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity. The EPSS score of less than 1 % suggests that exploitation is currently uncommon, but the risk remains because the flaw allows arbitrary script storage and execution. The issue is not listed in the CISA KEV catalog. Based on the characteristics of CSRF, the attack vector is web‑based and usually requires the victim to be a logged‑in administrator or another privileged user who will execute the forged request. An attacker could inject a malicious payload through a fabricated link or form that the authenticated user processes, leading to stored XSS.
OpenCVE Enrichment
EUVD