Impact
The vulnerability described is a Cross‑Site Request Forgery (CSRF) that allows an attacker to make a user’s browser store and later execute arbitrary JavaScript under the plugin’s context. Because the payload is stored – not just transiently injected – any visitor to the affected WordPress site, including logged‑in administrators, can be exposed to malicious code.
Affected Systems
Blighty Explorer plugin for WordPress, all releases up to and including version 2.3.0. Sites that have not upgraded beyond this version are susceptible, regardless of whether they are running the latest minor release prior to 2.3.0.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity condition. The EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, meaning there are no publicly documented exploits. The issue is that a CSRF flaw allows an attacker to store arbitrary JavaScript within the Blighty Explorer plugin, which will be executed when the site is accessed. This stored XSS can impact the confidentiality and integrity of the site by enabling code execution in the context of visitors and administrators, but the specific downstream effects depend on the injected payload and are not detailed in the CVE description.
OpenCVE Enrichment
EUVD