Impact
A flaw in the Lewe ChordPress plugin permits an attacker to send a forged request that injects arbitrary script code into stored data. This Cross‑Site Request Forgery vulnerability results in Persisted XSS, allowing the attacker to compromise confidentiality and integrity of all users who view the affected content. The weakness is classified as CWE‑352, underscoring a failure to validate the authenticity of state‑changing requests.
Affected Systems
WordPress site running the Lewe ChordPress plugin, versions <=4.0.1. The vulnerability applies to all releases within this range, regardless of minor version differences.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity and the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to trick an authenticated user or an attacker’s browser into making the forged request; once the malicious script is stored, any visitor to the affected content will execute it.
OpenCVE Enrichment
EUVD