Impact
The vulnerability is a cross‑site request forgery flaw in the Funnnny HidePost plugin that allows reflected XSS. Based on the description, it is inferred that the plugin returns user‑controlled input without proper escaping, which can be reflected and executed as script by the victim’s browser. This flaw enables an attacker to craft a request that targets a vulnerable endpoint and inject malicious JavaScript, potentially compromising the session or data of any user who processes the request.
Affected Systems
Versions of the HidePost plugin from the earliest release through 2.3.8 are affected. WordPress installations that have the plugin installed and activated with any of these versions are vulnerable. The issue is confined to the Funnnny HidePost plugin and does not impact other WordPress components.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is reported as less than 1 %, indicating a low likelihood of current exploitation. It is not listed in the CISA KEV catalog, so no large‑scale active exploitation campaigns are known. The likely attack vector is a CSRF request sent by an attacker that targets a user who has the HidePost plugin endpoint accessible, thereby inducing the reflected XSS. The exploit requires user interaction and an authenticated or privileged session with permission to reach the vulnerable endpoint.
OpenCVE Enrichment
EUVD