Impact
The vulnerability combines Cross‑Site Request Forgery and stored cross‑site scripting. An attacker can craft a request that bypasses normal authentication checks and injects malicious JavaScript into content stored by the widget, which then executes in the browsers of anyone who views the related‑posts page. The flaw is identified as CWE‑352.
Affected Systems
The flaw affects the WordPress plugin "Related Posts Widget with Thumbnails" (advanced‑css3-related-posts-widget) version 1.2 and all earlier releases. It is distributed by wp‑buy and is commonly installed on sites displaying thumbnail‑based related posts.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity. The EPSS score of less than 1% signals a very low exploitation probability at present, and the vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
EUVD