Impact
The vulnerability is a Cross‑Site Request Forgery that allows an attacker to submit arbitrary data to the Best Posts Summary WordPress plugin, which is then stored and displayed to other site users. An attacker can inject malicious JavaScript that will execute in the browsers of any visitor who views the stored content, enabling account hijacking, data theft, or defacement. This flaw is based on CWE‑352.
Affected Systems
The flaw affects the aseem1234 Best Posts Summary WordPress plugin for all releases up to and including version 1.0. No patched release is mentioned; any installation of 1.0 or earlier is therefore susceptible. The plugin is distributed through the WordPress plugin repository under the name ‘Best Posts Summary’.
Risk and Exploitability
The CVSS score of 7.1 marks this as a high severity issue. The EPSS score of < 1% indicates that, as of now, the probability of exploitation is very low, but the vulnerability is not yet tracked in CISA’s KEV list. In practice, an attacker would need to lure a logged‑in administrator or contributor to the site into visiting a crafted URL or submitting a form that would trigger the CSRF. Inferred, the attack would then result in a stored XSS payload that any subsequent visitor to the affected content would execute.
OpenCVE Enrichment
EUVD