Impact
The World plugin for WordPress contains a Cross‑Site Request Forgery flaw that can be used to store malicious scripts. An attacker can inject JavaScript that will execute whenever any user views affected content, enabling theft of credentials, session hijacking, or defacement. The weakness is a client‑side code injection problem (CWE‑352).
Affected Systems
Users who have installed doa The World (The World plugin) version 0.4 or earlier on their WordPress site are affected. The vulnerability applies to all versions from the earliest variant up through 0.4.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability carries a moderate‑to‑high severity. The EPSS score of less than 1 percent indicates a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires the attacker to craft a forged web request that targets the plugin’s input handling, which can be performed from any browser that can reach the WordPress site. If a user unknowingly submits the forged request, the malicious script will become stored and executed for subsequent visitors.
OpenCVE Enrichment
EUVD