Impact
A cross‑site request forgery flaw in the WordPress WP Social Bookmarking plugin authorizes a malicious actor to construct a forged HTTP request that the plugin accepts and stores as legitimate content. The stored payload is executed when other site visitors view processed content, enabling script injection inside their browsers. This leads to potential theft of session cookies, credential hijacking, or defacement of user‑generated posts.
Affected Systems
The flaw is present in all releases of the PResponsive WP Social Bookmarking plugin up to and including version 3.6. Administrators of WordPress sites running this plugin in those versions should consider the application vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity, while an EPSS score of less than 1% points to a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalogue. Based on the description, it is inferred that exploitation most likely requires an authenticated user on the site, or a user who visits a crafted URL after authenticating, allowing the attacker to force the plugin to store malicious content.
OpenCVE Enrichment
EUVD