Impact
A Cross‑Site Request Forgery flaw in the WordPress plugin allows an attacker to submit a crafted request that stores malicious script code within the plugin’s data store. The stored code is later rendered on the site, enabling an attacker to perform session hijacking, data theft, or defacement. The flaw is classified as CWE‑352, indicating that a CSRF attack can result in stored cross‑site scripting.
Affected Systems
The vulnerability is present in the WordPress plugin "Complete SEO: Page/Post Specific Social Share Buttons" for all releases up to and including version 2.1. Any site running an affected version is at risk.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as High severity. The EPSS score indicates a very low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is CSRF; an attacker must obtain a legitimate user session with editing rights to the plugin. Once achieved, the attacker can submit a malicious request that stores a script, which is then executed in the context of site visitors.
OpenCVE Enrichment
EUVD