Impact
Cross‑Site Request Forgery (CSRF) vulnerability in Callmeforsox Post Thumbs allows an attacker to store malicious JavaScript in the database. Because the plugin lacks CSRF protection on write operations, an authenticated user can unknowingly submit the payload. The stored XSS can then execute in the context of future visitors, potentially compromising user sessions, defacing content, or exfiltrating data. The flaw is classified as CWE‑352.
Affected Systems
WordPress users running the callmeforsox Post Thumbs plugin, versions n/a through 1.5 inclusive, are affected. This includes all sites that have installed any version of the plugin equal to or older than 1.5. Users of newer releases are not impacted.
Risk and Exploitability
The CVSS score of 7.1 signifies a high‑impact threat, while the EPSS score of less than 1% indicates a low probability of exploitation at present. It is not yet listed in the CISA KEV catalog. Though not well known, the attack vector is inferred to be a CSRF scenario where an attacker persuades an authenticated administrator or author to visit a malicious link or submit a forged form, triggering the vulnerable endpoint. If executed, the stored XSS could jeopardize both data integrity and confidentiality for all users who view the compromised content.
OpenCVE Enrichment
EUVD