Impact
The subscriptiondna:Subscription DNA WordPress plugin contains a Cross‑Site Request Forgery flaw that allows an attacker to inject JavaScript that is stored and subsequently served to users. By tricking a victim into sending a forged request, the malicious code is persisted in the plugin’s data, enabling persistent cross‑site scripting when the victim later views the affected content. This combination of CSRF and stored XSS weaknesses could allow attackers to hijack sessions, deface pages, or exfiltrate information.
Affected Systems
This issue affects the Subscription DNA WordPress plugin versions up to and including 2.1. Any site running subscriptiondna as a plugin that is identified as version 2.1 or earlier is impacted.
Risk and Exploitability
The CVSS score of 7.1 signals a high‑severity vulnerability. The EPSS score of < 1% indicates a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would likely direct a logged‑in user to a malicious page that submits a forged request to the plugin, resulting in stored XSS that is later delivered when the user views related pages. Because the flaw is triggered via CSRF, the attack requires user interaction, but the impact remains significant if executed.
OpenCVE Enrichment
EUVD