Impact
A Cross‑Site Request Forgery flaw in the MMX – Make Me Christmas WordPress plugin permits an attacker to submit a forged request that is stored by the plugin and later rendered as executable script. This leads to Stored XSS, enabling the execution of arbitrary JavaScript in the context of the site, potentially capturing user credentials, defacing content, or hijacking sessions. The weakness is identified as a CSRF vulnerability (CWE‑352).
Affected Systems
The vulnerability affects the MMX – Make Me Christmas plugin, version 1.0.0 and earlier, for WordPress installations. Any WordPress site that has installed this plugin within that version range is susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely a CSRF request, which requires an authenticated user to click a malicious link; the attacker does not need remote code execution or vulnerability exploitation before planting the script. While exploitation complexity is low, the impact on confidentiality and integrity of a compromised site can be significant.
OpenCVE Enrichment
EUVD