Impact
WordPress plugin orlandolac's Facilita Form Tracker contains a Cross‑Site Request Forgery flaw that permits an attacker to store malicious script in the plugin’s data. After the script is stored, it is rendered on the frontend and executed in any visitor’s browser, potentially allowing cookie theft, defacement, or further compromise. The vulnerability is a classic example of CWE‑352.
Affected Systems
WordPress sites running orlandolac Facilita Form Tracker version 1.0 or earlier. No later versions are reported to be affected.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate-to-high severity, while the EPSS score of less than 1% suggests a low current probability of exploitation. The issue is not listed in the CISA KEV catalog. An attacker could exploit this by tricking an authenticated user into submitting a forged request that injects stored script, which will then be executed for all site visitors.
OpenCVE Enrichment
EUVD