Impact
A Cross‑Site Request Forgery vulnerability in the WordPress Content Snippet Manager plugin allows an attacker to trigger a request that stores arbitrary script code as a content snippet. Once stored, the malicious code executes in the browsers of anyone who views the affected snippets, potentially compromising user data, session cookies, or facilitating further phishing attacks.
Affected Systems
WordPress sites running the alexvtn Content Snippet Manager plugin version 1.1.5 or older are vulnerable. The affected product is the Content Snippet Manager plugin.
Risk and Exploitability
The CVSS base score of 7.1 indicates high severity, yet the EPSS score of less than 1% shows a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to persuade a site user with sufficient permissions (e.g., admin or contributor) to visit a crafted URL, where the CSRF request silently stores the malicious snippet. Once stored, the XSS payload runs for all subsequent visitors of the site.
OpenCVE Enrichment
EUVD