Impact
This CVE describes a Cross‑Site Request Forgery flaw in the Bknewsticker WordPress plugin that permits an attacker to embed malicious script into the site’s content. By forging a request, the payload is stored and later executed when a visitor loads the affected page. The weakness is classified as CWE‑352, indicating insufficient protection against unauthorized request forging.
Affected Systems
WordPress sites running the Bknewsticker plugin version 1.0.5 or earlier are affected. The plugin is distributed by the vendor beke_ro under the product name Bknewsticker.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity vulnerability. The EPSS score of less than 1% suggests exploitation attempts are currently rare, and the issue is not listed in CISA’s KEV catalog. Because the flaw allows stored XSS through an unauthorized request, an attacker could influence content presented to site visitors; however, the CVE data does not specify the exact conditions or privileges required for exploitation.
OpenCVE Enrichment
EUVD