Impact
The vulnerability is a Cross‑Site Request Forgery flaw that permits an attacker to inject deceptive content which is stored in the database, yielding persistent Cross‑Site Scripting. This stored XSS can execute arbitrary code in the context of the site, allowing attackers to steal user sessions, deface pages, or hijack administrative functions. The weakness is identified as CWE‑352.
Affected Systems
WordPress sites using the Sudavar Codescar Radio Widget plugin version 0.4.2 or earlier are affected. No other products are listed.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high severity, while the EPSS score of less than 1% suggests exploitation is unlikely at present. The flaw is not catalogued in CISA’s KEV list. Inferred attack vectors involve an authenticated user with the plugin enabled; a forged request from a malicious site could inject the harmful payload. Once stored, the payload executes whenever the content is rendered to users.
OpenCVE Enrichment
EUVD