Impact
A Cross‑Site Request Forgery (CSRF) vulnerability in the WordPress Login Alert plugin allows an attacker to store malicious scripts that are later executed by any user who views the affected content. Once the payload is stored in the database, it can run in the browser context of visitors or administrators, potentially exfiltrating credentials, hijacking sessions, or defacing the site. The weakness is a classic Stored XSS scenario triggered by CSRF.
Affected Systems
PasqualePuzio Login Alert plugin versions up to and including 0.2.1 are affected. All installations using these releases are vulnerable, regardless of whether the plugin is used for login alerts or other features.
Risk and Exploitability
The CVSS score of 7.1 classifies this issue as High severity. The EPSS score of less than 1% indicates that exploitation is relatively unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker inducing a logged‑in user or administrator to unknowingly submit a crafted request that stores an XSS payload via the plugin. Once stored, the payload runs in any subsequent page load, making the vulnerability widely exploitable across all users that view the affected content.
OpenCVE Enrichment
EUVD