Impact
Cross‑Site Request Forgery in the ReviewsTap plugin allows malicious actors to inject script into stored review content, which will execute in the browsers of any visitor viewing the affected page. The flaw results in a stored XSS condition, enabling attackers to run arbitrary JavaScript, deface the site, or harvest sensitive data from user sessions. This is a typical input‑validation weakness identified by CWE‑352.
Affected Systems
The vulnerable component is the awcode ReviewsTap WordPress plugin. All releases from the initial (n/a) version up to and including 1.1.2 are affected. WordPress sites that have the ReviewsTap plugin installed and have not updated to a non‑vulnerable release are at risk.
Risk and Exploitability
The CVSS score is 7.1, indicating high severity. Because the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV, the likelihood of widespread exploitation is currently low, though it remains a significant concern for sites that rely on the plugin's review storage features. Exploitation requires a victim user to be logged in to trigger the CSRF, after which the stored payload will run automatically in any subsequent page view. The attack vector is inferred to involve a logged‑in user interacting with a crafted link or form.
OpenCVE Enrichment
EUVD