Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to insert malicious scripts into the plugin’s storage. By sending a crafted request, a logged‑in user can cause the plugin to save arbitrary JavaScript that is then executed when any user views the affected content, resulting in stored XSS. This permits an attacker to hijack sessions, deface sites, or perform other malicious actions with the privileges of the affected users.
Affected Systems
The issue affects the Eli:EZ SQL Reports Shortcode Widget and DB Backup WordPress plugin versions from the earliest release through 5.25.08. Any WordPress site that has installed this plugin and is running a version ≤5.25.08 is susceptible.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating a high severity. The EPSS score is below 1 % so current exploitation probability is low. The plugin is not listed in CISA’s KEV catalog. The attack vector is inferred to be web‑based: an attacker must send a CSRF request that a privileged visitor executes. If the visitor has sufficient permissions, the stored payload will be rendered for all site users, making the risk significant for sites with broad user access.
OpenCVE Enrichment
EUVD