Impact
A Cross‑Site Request Forgery flaw in the WP Cookies Alert plugin permits an attacker to inject malicious script into the plugin’s configuration. Once stored, the payload is executed when users view the affected page, delivering a stored XSS attack that can compromise confidentiality and integrity of the visited site.
Affected Systems
The issue affects the aleapp WP Cookies Alert plugin for WordPress, versions from the initial release up through 1.1.1. WordPress sites with this plugin installed at or below version 1.1.1 are vulnerable.
Risk and Exploitability
The CVSS base score is 7.1, indicating high severity. The EPSS score is below 1 %, suggesting low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a web‑based CSRF attack against an authenticated administrator or privileged user who submits a forged request that stores the malicious script. No additional prerequisites are specified in the CVE data.
OpenCVE Enrichment
EUVD