Impact
The WPFactory Custom CSS, JS & PHP WordPress plugin contains a Cross‑Site Request Forgery flaw that allows an attacker to inject arbitrary PHP code through the custom‑css interface. A user who is already authenticated can be tricked into loading a crafted request, which results in remote code execution on the server, compromising confidentiality, integrity, and availability. The weakness is classified as CWE‑352.
Affected Systems
The vulnerability affects the Custom CSS, JS & PHP plugin for all releases from the earliest available version up to and including 2.4.1. No later releases are known to be affected and the fix is presumed to be included in versions released after 2.4.1.
Risk and Exploitability
The CVSS score of 9.6 indicates an extremely high severity, while the EPSS score of less than 1 % suggests a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Inference: the likely attack vector is a web‑based CSRF attack that requires an authenticated administrator to be logged in when a malicious link is followed, enabling the attacker to gain total control of the affected WordPress installation.
OpenCVE Enrichment
EUVD