Impact
This vulnerability allows an attacker to perform a cross‑site request forgery that results in stored cross‑site scripting. By forging a request from a victim, the attacker can embed a malicious script into the plugin’s data store, which will later be rendered in the browsers of all site visitors. The effect is that arbitrary code can be executed in the context of the website, enabling session hijacking, data theft, and defacement.
Affected Systems
Affected systems: ZIPANG Simple Stripe plugin installed in WordPress sites with version 0.9.17 or earlier. All other versions are not affected.
Risk and Exploitability
Risk and exploitability: The CVSS score is 7.1, indicating a high severity. EPSS is below 1 %, suggesting exploitation is unlikely in the current threat landscape. The vulnerability is not indexed in the CISA KEV catalog. Exploit requires a user to be tricked into visiting a forged URL that submits a malicious request, which then persists a script in the site’s database and is delivered to downstream users. As no public exploit has been reported, the immediate threat level is moderate but mitigable with prompt remediation.
OpenCVE Enrichment