Impact
The vulnerability is a Cross‑Site Request Forgery flaw that permits attackers to inject malicious JavaScript into content stored by the WP Map Route Planner plugin. This stored XSS can compromise confidential user information or allow malicious code execution for all visitors who view the affected content. Based on the description, the likely attack vector involves an authenticated user being tricked into submitting a forged request that embeds the script, which is then stored and rendered by the plugin.
Affected Systems
The flaw is present in all releases of the Vsourz Digital WordPress plugin WP Map Route Planner version 1.0.0 and earlier. Any WordPress installation that uses this plugin before upgrading to a later, patched release is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity. The EPSS score of less than 1 percent suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Although exploitation is improbable at present, the absence of CSRF tokens allows an attacker to attempt to trick an authenticated user into submitting a forged request that stores the malicious script, without requiring direct access to the site’s admin console.
OpenCVE Enrichment
EUVD