Impact
The RSS Filter plugin contains a CSRF weakness that permits an attacker to inject malicious JavaScript into the plugin’s data storage; a crafted request submitted by a logged‑in administrator or privileged user can result in persistent XSS that affects every user who views the RSS feed, enabling credential theft, defacement or other session hijacking attacks.
Affected Systems
The vulnerability affects the RSS Filter plugin developed by Shambhu Patnaik, versions up to and including 1.2; any WordPress installation running one of these versions is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, and the very low EPSS score of <1% suggests that, so far, exploitation is unlikely in the wild, though the existence of a working exploitation method means the risk is present. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the bug via a CSRF vector by luring an authenticated user to a crafted link or form; the injected script will execute in all browsers that load the affected feed without requiring additional conditions such as remote code execution.
OpenCVE Enrichment
EUVD