Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to supply malicious input that the plugin stores in its database. When the stored content is subsequently displayed to visitors, the attacker’s script executes in their browsers, creating a persistent cross‑site scripting condition.
Affected Systems
WordPress sites running the wp‑buy related‑Posts‑list‑grid‑and‑slider‑all‑in‑one plugin, version 3.0.0.1 or older. The flaw applies to all releases from an undefined starting version up to and including 3.0.0.1.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity, while the EPSS of less than 1% indicates a low probability of current exploitation. The flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack path involves an attacker tricking a logged‑in user into submitting a crafted request that bypasses CSRF protection, causing malicious data to be stored and then rendered as part of the content seen by all users of the site.
OpenCVE Enrichment
EUVD