Impact
The vulnerability allows attackers to perform a cross‑site request forgery that stores malicious script code within the plugin. Once the script is stored, it will execute in the browsers of users who view the compromised content, potentially leaking credentials or enabling further compromise. The weakness is a classic CSRF flaw (CWE-352).
Affected Systems
WordPress sites running the Epeken All Kurir plugin versions from the base build up to and including 2.0.6 are affected. All installations of this plugin, regardless of user role, are at risk if not upgraded.
Risk and Exploitability
The CVSS score of 7.1 reflects a high‑impact security flaw. The EPSS score of less than 1% indicates that the probability of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Inferred from the description, the attack vector requires a victim with authenticated permissions to trigger the request, suggesting that compromised or privileged users could be abused to inject the stored XSS payload. Once injected, the payload could execute in the context of any site visitor, leading to data theft or session hijacking.
OpenCVE Enrichment
EUVD