Impact
A Cross‑Site Request Forgery vulnerability in the WP Custom Post RSS Feed plugin allows an attacker to submit a forged request that stores malicious scripts in the plugin’s data. Those scripts are then rendered in the RSS feed, providing stored XSS that can be executed when visitors access the feed.
Affected Systems
WordPress sites that have installed Cynob IT Consultancy’s WP Custom Post RSS Feed plugin, versions from the initial release up through 1.0.0 are affected.
Risk and Exploitability
The CVSS score of 7.1 classifies this as a high‑severity vulnerability. The EPSS score of less than 1% indicates a low probability that exploitation attempts are occurring. The vulnerability is not currently listed in CISA’s KEV catalog, and no known public exploit is reported. The likely attack vector is a crafted HTTP request targeted at the plugin’s administrative endpoint that bypasses standard CSRF protection, enabling the attacker to inject and store persistent malicious scripts.
OpenCVE Enrichment
EUVD