Impact
This vulnerability allows an attacker to carry out a cross‑site request forgery that results in malicious script code being stored in the CG Scroll To Top plugin data. When the plugin processes a request, the attacker’s script is persisted and later delivered to site visitors, causing arbitrary client‑side code to execute in the context of the website. The flaw is a classic stored XSS caused by inadequate protection against CSRF, identified as CWE‑352.
Affected Systems
The CG Scroll To Top plugin developed by Chandan Garg, versions up through 3.5, is affected. Any WordPress site that has installed or retained a version through 3.5 of this plugin is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while an EPSS score of less than 1% suggests exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires a CSRF request originating from a trusted context or persuading an authenticated user to submit a carefully crafted request. Because the flaw results in stored XSS, the impact can persist and affect all site users visiting compromised pages. The overall risk remains moderate to high for sites that have not applied a fix.
OpenCVE Enrichment
EUVD