Impact
A Cross‑Site Request Forgery vulnerability in the Revision Diet WordPress plugin allows an attacker to forge an authenticated request that injects and stores arbitrary JavaScript. The injected script is executed in the context of any user who views the affected content, leading to data theft, session hijacking, or defacement.
Affected Systems
The issue impacts the David Miller Revision Diet plugin for WordPress versions up to and including 1.0.1. Any WordPress site running this plugin and with users able to submit revisions is potentially affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, with the EPSS score of less than 1% showing a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by sending a crafted request from a malicious site to a logged‑in user’s browser, taking advantage of the lax CSRF protection in the plugin. Successful exploitation results in persistent client‑side code that survives site refreshes.
OpenCVE Enrichment
EUVD