Impact
Cross‑Site Request Forgery in the Social Crowd plugin for WordPress enables attackers to inject persistent malicious scripts. By forging a legitimate request that a logged‑in user submits, the attacker can cause the site to store arbitrary JavaScript code. When other visitors load the affected content, the code runs in their browsers, potentially stealing credentials, defacing content, or hijacking sessions. The flaw stems from inadequate CSRF protection and aligns with CWE‑352.
Affected Systems
The affected product is the WordPress Social Crowd plugin supplied by bdoga, version 0.9.6.1 and earlier. Any installation of Social Crowd that has not been updated beyond 0.9.6.1 is vulnerable. The flaw exists in all builds of the plugin from the earliest available version up to 0.9.6.1 inclusive.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability represents a medium‑to‑high risk. The EPSS score of less than 1% indicates that exploitation is currently unlikely, and the flaw is not listed as a known exploited vulnerability by CISA. Attackers are presumed to use a CSRF technique that requires the victim to have an active session on the site, such as a logged‑in administrator or content editor, after which they can embed malicious JavaScript that will persistently affect all users who view the exploited content.
OpenCVE Enrichment
EUVD