Impact
The vulnerability is a Cross‑Site Request Forgery that enables an attacker to store malicious JavaScript in the WordPress Floating Window Music Player plugin. When users load the plugin’s content, the injected script executes in the context of the site, allowing defacement, cookie theft, and other client‑side attacks. The flaw permits execution of arbitrary code on a user’s browser, compromising confidentiality and integrity of user sessions.
Affected Systems
The issue affects the WordPress plugin Floating Window Music Player by ericzane, impacting all installed versions up to and including 3.4.2. Any WordPress site running this plugin without an applied fix is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, but the EPSS score of less than 1% suggests a low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be website owners or administrators who can send forged requests that result in stored malicious payloads. If exploited, a single administrative session could compromise all site visitors.
OpenCVE Enrichment
EUVD