Impact
The Smart DoFollow plugin has a Cross‑Site Request Forgery (CWE‑352) vulnerability that allows an attacker to inject malicious script into the plugin’s stored data. Once stored, the script executes in the browsers of all visitors to the site, enabling the attacker to steal cookies, deface content, or perform other malicious actions within the context of authenticated users. The primary impact is the persistence of malicious code that runs on every subsequent visit.
Affected Systems
The vulnerability affects the Smart DoFollow WordPress plugin, version 1.0.2 and earlier, from the vendor LukaszWiecek. Any WordPress site that has installed a vulnerable version of this plugin is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack vector requires an attacker to coerce an authenticated user (for example, an administrator) into visiting a crafted link that submits a CSRF request, thereby storing the malicious script. This is inferred from the nature of CSRF and the requirement to perform privileged actions on behalf of the user.
OpenCVE Enrichment
EUVD