Impact
This vulnerability permits an attacker to forge a request that causes the plugin to store a malicious script. The script is then executed in the browsers of users who view the affected content, allowing the attacker to run arbitrary code in the victim’s browser. The weakness is a Cross‑Site Request Forgery that leads to Stored Cross‑Site Scripting (CWE‑352).
Affected Systems
Krzysztof Furtak’s KK I Like It WordPress plugin, versions 1.7.5.3 and earlier on any WordPress site that has the plugin installed.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as High severity. The EPSS score of less than 1 % indicates that widescale exploitation is currently considered unlikely. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires the attacker to trick a logged‑in user, or a malicious domain, into submitting a forged request that stores the malicious script via the plugin’s interface. Once the script is stored, it can be triggered when the content is rendered by other users or administrators.
OpenCVE Enrichment
EUVD