Impact
The vulnerability is a CSRF flaw that allows an attacker to trick an authenticated WordPress user into submitting malicious input that the Scroll Styler plugin stores as page or post content. When the stored content is later rendered, users visiting the affected page experience cross-site scripting attacks. This can lead to session hijacking, credential theft, or malicious use of the victim’s account. The weakness is identified as CWE-352 – Cross‑Site Request Forgery.
Affected Systems
WordPress installations running the jablonczay Scroll Styler plugin version 1.1 or earlier. Any site that has the plugin installed with that version range is susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk. The EPSS score of less than 1% shows a low probability of exploitation in the wild at this time, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the likely attack vector is a CSRF request from a malicious external site that forces a logged-in user to submit the forged form. Because the stored payload is rendered unfiltered, a compromised user’s browser can execute JavaScript, giving the attacker control over the site context.
OpenCVE Enrichment
EUVD