Impact
The vulnerability in the Chaser324 Featured Posts Scroll plugin permits attackers to forge requests that result in stored cross‑site scripting. This is a CWE-352 (Cross‑Site Request Forgery) flaw arising from insufficient verification of user intent, allowing malicious actors to inject JavaScript into content that is subsequently served to visitors. This stored XSS can compromise user accounts, steal credentials, or deliver malware.
Affected Systems
This issue impacts the WordPress plugin named Featured Posts Scroll from the Chaser324 author, affecting all releases from the earliest version through and including version 1.25. Sites that deploy any of these plugin versions with default settings are potentially vulnerable. No additional sub‑version constraints were disclosed.
Risk and Exploitability
The CVSS score of 7.1 indicates significant impact, while the EPSS score of less than 1 % suggests that exploitation attempts are currently rare. The flaw is not listed in the CISA KEV catalog. Attackers would likely need to coerce a privileged user into submitting a crafted request, making the attack path reliant on social engineering or compromised accounts. Once injected, the XSS payload remains stored and will be executed whenever the affected content is rendered, providing persistent exploitation potential. The likely attack vector is CSRF; attackers may embed malicious URLs or forms that the site owner is tricked into submitting.
OpenCVE Enrichment
EUVD