Impact
The Smart Product Gallery Slider plugin contains a Cross‑Site Request Forgery flaw that can be used to perform a stored Cross‑Site Scripting attack. A malicious actor can trick a logged‑in user into sending a forged request which stores arbitrary JavaScript in the plugin. When other visitors load the affected gallery, the injected script executes in the context of the site.
Affected Systems
The plugin is developed by Shameem Reza (Smart Product Gallery Slider). Versions from the initial release up to and including 1.0.4 are affected. No later versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity. The EPSS score of less than 1 percent suggests exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is a malicious CSRF request that persists an XSS payload. An attacker needs no special credentials beyond the ability to trick a logged‑in user into visiting a crafted URL or embedding a malicious element that triggers the vulnerability.
OpenCVE Enrichment
EUVD