Impact
The vulnerability is a Cross‑Site Request Forgery flaw that can be abused to inject malicious JavaScript into stored content in the WP Abstracts plugin’s manuscripts manager. The flaw allows an attacker to send a forged request from a victim’s browser that stores a script; later, when other users view the affected manuscript, the payload executes. This can lead to information theft, session hijacking, or defacement. The weakness is identified as CWE‑352.
Affected Systems
The flaw is present in all versions of the WP Abstracts plugin by Kevon Adonis up to and including 2.7.5. Any WordPress site installing the plugin before this version is affected. No further version ranges are provided.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% suggests exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Attackers likely need a victim who is logged into WordPress and a malicious link to trigger the CSRF request, making the threat moderate in practicality but serious if successful.
OpenCVE Enrichment
EUVD