Impact
Leadfox for WordPress plugin versions up to 2.1.9 contain a CSRF vulnerability that allows an attacker to submit requests on behalf of an authenticated administrator. The flaw can cause malicious data, such as scripts, to be stored in the plugin’s data store, which may later be rendered in users’ browsers, resulting in a stored cross‑site scripting execution.
Affected Systems
The vulnerability affects the Leadfox for WordPress plugin in WordPress installations when version 2.1.9 or earlier is installed and the plugin has not been updated. Sites running any such version are susceptible.
Risk and Exploitability
The CVSS score of 7.1 signals a high severity impact. The EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to craft a request that is processed by an authenticated administrator, typically via a malicious link or embedded form that triggers the stored data to be uploaded. Once stored, the script executes for all visitors who view the content, exposing the site to cross‑site scripting attacks.
OpenCVE Enrichment
EUVD