Impact
The vulnerability allows an attacker to forge a request that causes the plugin to store a malicious script payload. Once stored, the script is executed in the browsers of any user who views pages that load the plugin’s content, providing the attacker with the ability to run arbitrary JavaScript, steal session cookies, or deface the site. This is a classic stored XSS scenario driven by a CSRF weakness.
Affected Systems
Infoway LLC Ebook Downloader plugin version 1.0 or earlier is affected. No other versions have been confirmed. The plugin is a WordPress component, meaning any site running the affected plugin is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is less than 1 %, suggesting a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector requires a victim to trigger a forged request, which could be done via a malicious link or phishing email. Once triggered, the stored XSS can impact confidentiality, integrity, and availability of the site for all users.
OpenCVE Enrichment
EUVD