Impact
The vulnerability is a CSRF flaw that permits an attacker to indirectly inject malicious JavaScript that is stored within the application. If exploited, the attacker can place arbitrary scripts in content managed by theMarketer plugin, which will later be rendered in users′ browsers, potentially leading to session hijacking, credential theft, or defacement. The weakness is classified as CWE‑352 Cross‑Site Request Forgery.
Affected Systems
This issue affects theMarketer plugin versions up to and including 1.4.7. All WordPress sites that have the plugin installed at any version from the initial release up to 1.4.7 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity flaw, while the EPSS is under 1 %, suggesting a low probability of widespread exploitation at present. The vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires a user to be authenticated to the site, and the attacker can perform the CSRF by sending a crafted request from a malicious site or email; the impact is that any content the attacker can force to be saved via the plugin will be executed in other users′ browsers, based on the nature of CSRF, the attacker likely needs a logged‑in user, though the description does not explicitly state this.
OpenCVE Enrichment
EUVD