Impact
The vulnerability in the Roi Calculator plugin allows an attacker to trick a legitimate site user into submitting a request that contains a malicious script. After the request is processed, the script is stored in the site’s content and then executed whenever the stored content is displayed, giving the attacker the ability to run arbitrary code in the victim’s browser. The weakness is a Cross‑Site Request Forgery (CWE‑352) that leads to a Stored Cross‑Site Scripting flaw, which can compromise confidentiality, integrity, and availability of the site and its visitors.
Affected Systems
The affected product is the mgplugin ROI Calculator plugin for WordPress, versions from the earliest available through version 1.0. All releases up to and including 1.0 are vulnerable; no newer versions are noted in the CVE data.
Risk and Exploitability
The severity score of 7.1 indicates a high risk. The EPSS score of less than 1% suggests that exploitation is relatively rare but still possible. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need the target user to visit a crafted URL or otherwise submit a forged request while authenticated. Once the malicious input is stored, it can affect all users who view the compromised content.
OpenCVE Enrichment
EUVD