Impact
The flaw is a CSRF vulnerability in the Ab‑Tools Flags Widget plugin for WordPress that allows an attacker to store arbitrary JavaScript through a request that bypasses the plugin’s CSRF protection. Once the malicious script is stored, it executes in the browser every time the widget content is rendered, enabling client‑side compromise when site visitors view the widget.
Affected Systems
Ab‑Tools Flags Widget plugin for WordPress, any version from the earliest available up to and including 1.0.7.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as moderate to high impact. The EPSS score of less than 1 % suggests a low likelihood of exploitation currently, and the vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit this by sending a crafted request that bypasses the missing CSRF check, causing the stored script to execute whenever the widget is displayed to a user.
OpenCVE Enrichment
EUVD