Impact
The vulnerability is a Cross‑Site Request Forgery flaw that permits an attacker to inject malicious scripts into the WordPress Twitter Card Generator plugin’s data store. This results in stored cross‑site scripting, enabling the attacker to execute arbitrary code in the browsers of anyone who views the forged content, thereby compromising confidentiality, integrity, and the overall user experience.
Affected Systems
The affected product is the silencecm Twitter Card Generator plugin for WordPress. Versions from the earliest available (no minimum) up to and including 1.0.5 are vulnerable. Upgrading beyond 1.0.5 removes the flaw.
Risk and Exploitability
The CVSS score of 7.1 denotes medium‑to‑high severity. The EPSS score of less than 1% indicates a low exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an authenticated user or an attacker who can convince a user to visit a crafted link that exploits the CSRF vector, thereby storing malicious payloads that persist across sessions.
OpenCVE Enrichment
EUVD