Impact
The SensitiveTagCloud plugin for WordPress is vulnerable to Cross‑Site Request Forgery that allows an attacker to inject and store malicious scripts. The flaw is triggered by forging authenticated requests to the plugin’s endpoints, which are processed without adequate CSRF protection. Successful exploitation results in stored XSS on the site, enabling the attacker to steal credentials, deface content, or deliver malware.
Affected Systems
The vulnerability affects the Reneade SensitiveTagCloud plugin in all versions up through 1.4.1. Any WordPress site that has installed this plugin in a version 1.4.1 or earlier is impacted, regardless of the underlying WordPress version.
Risk and Exploitability
With a CVSS score of 7.1 and an EPSS of less than 1 %, the likelihood of exploitation remains low but not negligible. The vulnerability is not listed in the CISA KEV catalog. Attackers can provoke the action by sending a crafted HTTP request from a malicious website or email while the user is logged into WordPress. No elevated privileges or additional conditions are required beyond authenticated access.
OpenCVE Enrichment