Impact
The vulnerability allows an attacker to exploit a Cross‑Site Request Forgery flaw in the Smart Maintenance & Countdown WordPress plugin, enabling the injection of malicious JavaScript that is subsequently stored and executed on the site. This stored XSS can compromise user sessions, deface the site, or serve as a vector for further attacks. The likely attack vector involves the attacker crafting a malicious URL that a logged‑in administrator unwittingly visits, causing the plugin to persist the payload.
Affected Systems
WordPress installations running the Smart Maintenance & Countdown plugin version 1.2 or earlier are affected. The plugin is distributed under the vendor name gmnazmul.
Risk and Exploitability
The CVSS score of 7.1 classifies this flaw as high severity, yet the EPSS score of less than 1% indicates a very low probability of real‑world exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that a privileged user unintentionally triggers the CSRF payload, after which the stored script will execute for all subsequent site users.
OpenCVE Enrichment
EUVD