Impact
The Login-box plugin accepts data without verifying a CSRF token, allowing an attacker to submit malicious script that is stored and later executed on the site, enabling stored XSS attacks. This can lead to credential theft, defacement, or malicious actions in the context of authenticated users. The weakness is a Cross‑Site Request Forgery flaw that permits Stored XSS, identified as CWE‑352.
Affected Systems
All installations of the Danillo Nunes Login-box WordPress plugin with a version of 2.0.4 or earlier are affected. The vulnerability applies to any site that has the plugin active and allows users to submit data via the plugin’s interfaces.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high severity. The EPSS score is below 1 %, suggesting a low probability of observed exploitation at the time of this analysis. The flaw is not yet in the CISA KEV list. Exploitation requires a user with sufficient privileges to submit the stored payload, typically through a CSRF request crafted by an attacker, making the attack vector Web‑based.
OpenCVE Enrichment
EUVD