Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to inject malicious, permanently stored JavaScript into the WordPress admin area for the Venugopal Show notice or message on admin area plugin. Because the payload is stored, any subsequent visit to the affected admin page will execute the script, potentially enabling session hijacking, defacement, or redirection. The weakness is identified as CWE‑352.
Affected Systems
The affected product is the Venugopal Show notice or message on admin area plugin, versions up to and including 2.0. No further version details are listed.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity, while the EPSS score of less than 1% indicates a low current exploitation probability. It is not listed in CISA’s KEV catalog, suggesting no large‑scale exploitation has been reported yet. The likely attack path requires an authenticated WordPress administrator to visit a crafted link or submit a forged request, after which the stored XSS code will persist and execute on future admin page loads.
OpenCVE Enrichment
EUVD