Impact
A Cross‑Site Request Forgery flaw in the mendibass Browser Address Bar Color plugin permits attackers to store malicious script payloads that run in the context of privileged users. The injected code can read cookies, deface the site, or forward requests, enabling session hijacking or further attacks.
Affected Systems
The vulnerability affects the mendibass Browser Address Bar Color WordPress plugin in all releases up to and including version 3.3.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity flaw, while the EPSS score of less than 1% suggests very low exploitation probability at present. The attack can be carried out via a crafted HTTP request that a logged‑in administrator visits, resulting in stored XSS. The vulnerability is not listed in the CISA KEV catalog, implying no widely known active exploits yet.
OpenCVE Enrichment
EUVD