Impact
The Savyour Affiliate Partner plugin contains a CSRF vulnerability that allows attackers to perform stored cross‑site scripting. By forging a request, an attacker can inject malicious JavaScript into the site, which will execute under the context of any user who views the affected page. The flaw, classified as CWE‑352, enables an attacker to deface content, steal session tokens, or conduct phishing attacks among authenticated users.
Affected Systems
Affected systems are WordPress sites running the Savyour Affiliate Partner plugin version 2.1.4 or earlier. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. Since it relies on CSRF, an attacker typically needs a logged‑in user to submit a crafted request; however, once a malicious payload is stored, it will affect all subsequent visitors within the site, making the impact potentially widespread.
OpenCVE Enrichment
EUVD