Impact
Cross‑Site Request Forgery allows the Navegg Analytics plugin to store a malicious script in the database. When a user later loads the affected assets, that script will execute in the victim's browser. The vulnerability is a CSRF (CWE‑352) flaw that enables this client‑side code injection.
Affected Systems
The issue affects WordPress sites that have the Navegg Analytics plugin installed in any version up to and including 3.3.3. Any site running those versions is considered vulnerable.
Risk and Exploitability
With a CVSS score of 7.1, the flaw poses a substantial risk. The EPSS score of less than 1 % indicates that widespread exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves an attacker submitting a crafted request that bypasses CSRF checks, for example by embedding malicious POST data in a harmless webpage or by luring an authenticated user to a specific URL.
OpenCVE Enrichment
EUVD