Impact
A CSRF flaw in the Easy Custom CSS plugin allows an attacker to submit a forged request that is accepted by the currently logged‑in WordPress user. The forged request stores malicious JavaScript in the CSS that the plugin preserves, resulting in stored cross‑site scripting that executes whenever any page loads that CSS. This can enable session hijacking, cookie theft, or defacement of the site. The vulnerability is a classic stored XSS delivered through CSRF, linking to CWE‑352 and related CWE‑79 issues.
Affected Systems
All releases of the a.ankit Easy Custom CSS WordPress plugin from the earliest available version through version 1.0 are vulnerable. The flaw exists on every WordPress site that has the plugin installed and in use.
Risk and Exploitability
The CVSS score is 7.1, indicating high severity, while the EPSS score is below 1 %, implying low current exploit likelihood. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote: an attacker must create a crafted page that forces a logged‑in user to send the forged request, allowing the attacker to inject and store the malicious payload.
OpenCVE Enrichment
EUVD