Impact
A cross‑site request forgery flaw in the Marcin Kijak Noindex by Path plugin allows an attacker to submit a request that stores arbitrary scripts in the site’s database. When the stored code is later displayed to visitors, it can be executed in the browsers of anyone who loads the affected page.
Affected Systems
WordPress installations that have the Marcin Kijak Noindex by Path plugin installed, versions 1.0 or earlier.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑high severity, but the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a CSRF scenario in which an attacker constructs a malicious request that an authenticated user unknowingly submits, thereby instrumenting the plugin to record malicious code that will subsequently be served to site visitors.
OpenCVE Enrichment