Impact
A crafted request that bypasses the site’s CSRF defenses can inject malicious code into the WP Profitshare plugin’s stored data, resulting in stored XSS. The injected script would run in the browsers of visitors to pages that display the compromised content, providing an attacker with the ability to execute client‑side payloads.
Affected Systems
WordPress installations that have the ProfitShare.ro WP Profitshare plugin version 1.4.9 or earlier are affected. Administrators using any supported WordPress version with these plugin releases are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates medium‑to‑high severity, but the EPSS score of less than 1% suggests that exploitation likelihood is currently low. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers would need to craft a CSRF request that a privileged user or an authenticated user with sufficient rights would unknowingly submit, after which the stored payload would be rendered in the page, enabling a stored XSS attack.
OpenCVE Enrichment
EUVD