Impact
Cross‑Site Request Forgery in the Logo Manager For Samandehi plugin enables an attacker to inject malicious JavaScript that is stored in the system and executed in the context of any site visitor. This stored XSS can lead to credential theft, defacement, or the delivery of malware through forged sessions.
Affected Systems
The vulnerability affects the WordPress plugin Logo Manager For Samandehi published by Mohammad Parsa, versions from the earliest release through 0.5 inclusive. Any site running those plugin versions is susceptible.
Risk and Exploitability
Based on the description, it is inferred that attackers would exploit the CSRF vector by tricking an authenticated user into submitting a crafted request that stores malicious code, which then executes when other users view the affected content. The CVSS score of 7.1 indicates a high severity risk for confidentiality, integrity, and availability. The EPSS score of < 1% reflects a low likelihood of widespread exploitation at present, and the vulnerability is not listed in CISA KEV.
OpenCVE Enrichment
EUVD