Impact
The Wibiya Toolbar plugin for WordPress contains a Cross‑Site Request Forgery (CSRF) vulnerability identified as CWE‑352 that permits an attacker to store malicious script content. When a malicious user crafts a request that bypasses login checks, the plugin accepts the payload and persists it. Subsequent page loads render this script to visitors, enabling theft of session tokens, defacement, or further client‑side attacks, thereby compromising confidentiality and integrity of the site and its users.
Affected Systems
All WordPress sites running the Wibiya Toolbar plugin version 2.0 or earlier are affected. The vulnerability exists for every release up to and including 2.0, regardless of other plugin or theme configurations.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity, and the EPSS score of less than 1% indicates a low probability of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog. Exploitation requires that the vulnerable plugin be present and that the attacker can send a crafted CSRF request to the target WordPress site; it is a remote, web‑based attack that does not require local code execution.
OpenCVE Enrichment
EUVD