Impact
The WP User Stylesheet Switcher plugin contains a cross‑site request forgery flaw that allows an attacker to cause an authenticated administrator to submit a request that stores malicious JavaScript in the plugin’s settings. Once the injected script is loaded by visitors, it can steal cookies, deface content, or deliver malware. The weakness corresponds to the CWE‑352 "Cross‑Site Request Forgery" enumeration.
Affected Systems
The vulnerable versions are all releases of WP User Stylesheet Switcher from the initial release through v2.2.0, issued by developer vgstef. The plugin is used on WordPress sites to enable per‑user stylesheet selection; any site that has installed these or older plugin versions is affected.
Risk and Exploitability
The CVSS base score of 7.1 signals a high risk, but the EPSS score of less than 1 % indicates that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to convince or directly use a user with administrator privileges to trigger the malicious request, making the threat most acute for sites that allow web‑based admin logins.
OpenCVE Enrichment
EUVD