Impact
A Cross‑Site Request Forgery vulnerability in the WP Forum Server plugin allows an attacker to silently submit forged requests that result in stored Cross‑Site Scripting payloads. The flaw arises from inadequate request validation, permitting an authenticated user to perform actions on the site without explicit consent. The weakness is categorized as CWE‑352, pointing to missing anti‑CSRF protections that permit unauthorized state changes and XSS injection.
Affected Systems
WordPress installations that use the lucidcrew WP Forum Server plugin, any version of the plugin up to and including 1.8.2. The vulnerability applies to all releases from the earliest known version through 1.8.2.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk to confidentiality, integrity, and availability. The EPSS score of <1% shows a low probability of exploitation at present, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a web‑based interaction with the plugin’s endpoints, where an attacker can craft a forged request that, when submitted by a logged‑in user, stores an XSS payload on the forum. Adverse consequences include defacement, cookie theft, or lateral movement within the site.
OpenCVE Enrichment
EUVD