Impact
Cross‑Site Request Forgery found in the Spoiler Block plugin allows an attacker to inject malicious script that is stored in the site’s content. By sending a forged request that the plugin accepts without a proper CSRF token, the attacker can embed arbitrary script into a block. Once stored, the script executes in the browsers of any user—whether a regular visitor or an administrator—viewing that content, potentially enabling session hijacking, defacement, or phishing attacks. This flaw maps to CWE‑352.
Affected Systems
The vulnerability affects WordPress installations that use the Spoiler Block plugin from squiter, versions up to and including 1.7. No other products or vendors are listed as affected.
Risk and Exploitability
The CVSS severity of 7.1 places this issue in the High range, yet the EPSS score of < 1% indicates a very low current exploitation probability. The flaw is not catalogued in the CISA KEV, suggesting no widespread, actively exploited attacks have been reported. However, the stored‑XSS nature of the vulnerability means that any injected payload will persist and continue to affect users until removed or the plugin is patched. Exploitation requires the victim to be authenticated and to visit a malicious page that issues the forged request, making the attack plausible in a targeted scenario.
OpenCVE Enrichment
EUVD