Impact
The flaw is a Cross‑Site Request Forgery that allows a malicious actor to send a POST request accepted by the WordPress plugin WP Filter Post Category. The request includes code that is stored in the plugin’s data, and this code is subsequently served to any visitor of the affected content. The result is that arbitrary client‑side script can run in the browsers of site visitors.
Affected Systems
The WP Filter Post Category plugin from stesvis, all releases up through version 2.1.4, are affected.
Risk and Exploitability
The CVSS score of 7.1 denotes high severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The attacker must persuade a legitimate user with rights to modify plugin data to send the crafted request; based on the description, it is inferred that the user must be authenticated. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known large‑scale attacks.
OpenCVE Enrichment
EUVD