Impact
Cross‑Site Request Forgery (CSRF) in the WP Social Stream plugin allows an attacker to submit data that is stored by the plugin and executed as JavaScript when the page is rendered. This stored XSS flaw can result in the injection of malicious scripts that affect all visitors to the site. The vulnerability is classified under CWE–352 due to its reliance on covert request forwarding without proper validation.
Affected Systems
WordPress sites that use the WP Social Stream plugin from Nirmal Kumar Ram, including all released versions up to and including 1.1, remain exposed to this attack vector.
Risk and Exploitability
The CVSS score of 7.1 places the flaw in the moderate‑to‑high risk range. An EPSS value below 1% indicates a low probability of widespread exploitation at this stage, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the CVSS calculations and the nature of the weakness, it is inferred that an attacker would need to craft a CSRF request to the plugin’s form—likely requiring authenticated access to the administrative interface—to trigger the flaw, after which the malicious payload is permanently stored and executed for all site visitors.
OpenCVE Enrichment
EUVD