Impact
This vulnerability is a cross‑site request forgery flaw that allows an attacker to exploit the Listings for Buildium WordPress plugin by instructing an authenticated user to submit a crafted request. The request stores malicious JavaScript in the plugin’s data, resulting in persistent cross‑site scripting. The weakness is identified as a CSRF vulnerability (CWE‑352).
Affected Systems
Affects Deepak Khokhar’s Listings for Buildium plugin up to and including version 0.1.5. No further version information is available; all releases through 0.1.5 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium to high severity. The EPSS score of less than 1% suggests that the probability of exploitation presently is low, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an authenticated user who visits a malicious or infected page that issues the forged request, leading to stored XSS payloads that can affect all users who view the compromised listings.
OpenCVE Enrichment
EUVD