Impact
Missing authorization in the Czater.pl – live chat i telefon plugin allows an attacker to perform a cross‑site request forgery that stores malicious script code in the plugin database. When a victim’s browser loads the stored content, the script runs with the victim’s privileges, enabling cookie theft, session hijacking, or defacement. The weakness is identified as CWE‑862 – missing authorization.
Affected Systems
The vulnerability affects the WordPress plugin Czater.pl – live chat i telefon, versions up to and including 1.0.5. The plugin is installed on WordPress sites that provide live chat and telephone support functionality.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating a medium‑to‑high risk. The EPSS score of less than 1% suggests a low probability of exploitation, and it is not listed in the CISA KEV catalog. Attackers need an authenticated user’s session to trigger the CSRF, typically by luring the victim to a crafted link or embedding it in social media. Once executed, the stored XSS provides persistent script execution that can compromise the victim’s session or perform unauthorized actions on the site.
OpenCVE Enrichment
EUVD