Impact
A CSRF weakness in the Recent Posts Slider Responsive plugin allows an attacker to submit a request that stores malicious JavaScript code on the website. When a legitimate user with sufficient privileges visits the site, the injected script runs in their browser context, potentially stealing cookies, session data or defacing content. The vulnerability is identified as CWE‑352 and leads to a Stored XSS condition.
Affected Systems
The issue affects the "Recent Posts Slider Responsive" plugin from vendor dilemma123, for all released versions through and including 1.0.1. No specific patch versions are listed in the CNA, but the vulnerability exists in any copy of the plugin up to that revision.
Risk and Exploitability
With a CVSS score of 7.1 the flaw is considered high severity, yet the EPSS score of less than 1 percent suggests a low probability of immediate exploitation in the wild. The attack requires a valid user session, likely an administrator, to submit the malicious request. The flaw is currently not listed in the CISA KEV catalog, so there is no evidence of a large‑scale exploit campaign at present.
OpenCVE Enrichment
EUVD