Impact
Cross‑Site Request Forgery allows an attacker to impersonate an authenticated WordPress user and submit requests to the CheckBot plugin, resulting in the storage and later execution of malicious JavaScript on the site. The description indicates a Stored XSS vulnerability, but the specific consequences such as session hijack, defacement, or phishing are not explicitly stated; based on the nature of stored XSS, it is inferred that these outcomes could occur. The impact could affect confidentiality, integrity, and availability of the website, although the extent is not quantified.
Affected Systems
WordPress sites using the CheckBot plugin, version 1.05 or earlier. The vulnerability impacts the CheckBot checkbot add‑on available for WordPress installation and removal via the WordPress plugin interface.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity, and the EPSS score of <1% indicates a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to target an authenticated user or persuade a user to click a crafted link to trigger the CSRF request; no remote code execution or privileged escalation is required.
OpenCVE Enrichment
EUVD