Impact
A Cross‑Site Request Forgery vulnerability in the WordPress Issuu Panel plugin allows an attacker to submit a malicious payload that is stored on the site and executed for all users as stored XSS, compromising the integrity of the content presented to visitors.
Affected Systems
The vulnerability affects the WordPress Issuu Panel plugin for the operationsissuu “Issuu Panel” product, all versions from the earliest release up to and including 2.1.1.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑risk flaw, while the EPSS score of < 1% suggests that exploitation is considered rare. The vulnerability is not listed in CISA KEV. The flaw can be triggered using a forged request; an attacker would typically need to exploit an authenticated user’s session or rely on the user to initiate a POST request, a condition inferred from the nature of CSRF attacks.
OpenCVE Enrichment
EUVD