Impact
Cross‑Site Request Forgery in the Easy Related Posts plugin allows an attacker to inject malicious JavaScript that will be stored and then displayed to other visitors. The stored XSS can lead to session hijacking, defacement, or further malware delivery. The flaw is identified as a cross‑site request forgery that results in persistent client‑side code execution.
Affected Systems
The vulnerability affects the WordPress plugin Easy Related Posts from the developer xdark. Any installation that uses version 2.0.2 or earlier is potentially compromised, as the issue has not been mitigated in releases prior to 2.0.3.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity risk, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed widespread exploitation yet. Attackers would need to obtain the ability to submit malicious content, which is possible through CSRF; the attack vector is inferred to be a standard web‑based forgery that results in stored scripts.
OpenCVE Enrichment
EUVD