Impact
The CVE describes a Cross‑Site Request Forgery that permits stored cross‑site scripting within the SCAND MultiMailer WordPress plugin. An attacker can cause the plugin to save malicious script. This script is then served to any visitor of the affected pages, potentially allowing a persistent client‑side attack such as defacement, data exfiltration, or other browser‑based exploitation. The weakness is identified as CWE‑352.
Affected Systems
The Vulnerability affects all installed instances of the SCAND MultiMailer WordPress plugin version 1.0.3 and earlier. Any WordPress site that has not upgraded beyond 1.0.3 remains exposed regardless of the host’s WordPress core version.
Risk and Exploitability
The CVSS score of 7.1 indicates significant risk while the EPSS score of less than 1% suggests a low immediate exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a forged request containing malicious script. Based on the description, it is inferred that the attacker must trick a user into sending such a request, but the level of user privilege required is not specified. Once the malicious script is stored, it will execute for any user who views the affected content.
OpenCVE Enrichment
EUVD