Impact
The Script Compressor plugin for WordPress contains a Cross‑Site Request Forgery vulnerability that permits an attacker to submit a forged request that stores malicious JavaScript in the site’s configuration or content. The injected script is executed in the browsers of anyone who views the affected page, enabling cookie theft, session hijacking, defacement, or other credential‑stealing attacks. This flaw is identified as CWE‑352, a classic CSRF leading to stored XSS.
Affected Systems
The vulnerability affects the WordPress plugin known as Script Compressor, managed by the vendor regen, for all releases up to and including version 1.7.1. Sites running this plugin without patching expose themselves to the risk described above.
Risk and Exploitability
The CVSS score of 7.1 places the flaw in the high‑moderate risk range. The EPSS score is below 1%, indicating that exploitation attempts are currently very few, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the attack vector is a typical CSRF leading to stored XSS, an attacker only needs a victim to submit a crafted request—often through a malicious link or embedded image—to trigger the vulnerability.
OpenCVE Enrichment
EUVD