Impact
A Cross‑Site Request Forgery flaw in the Looks Awesome OnionBuzz plugin allows an attacker to submit malicious content that is then stored on the site. The stored data can contain JavaScript, enabling an attacker to execute code whenever any user views the affected content. This results in a Stored XSS condition that compromises the confidentiality and integrity of the site’s data and can hijack user sessions.
Affected Systems
WordPress sites running the Looks Awesome OnionBuzz plugin version 1.0.7 or earlier are affected. The plugin is distributed under the "onionbuzz-viral-quiz" component and may appear on any site that has installed the older plugin.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score of less than 1% shows that exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to trick a user into visiting a crafted URL or form to trigger the CSRF request that stores malicious payloads. While the exploitation window is narrow, the resulting Stored XSS can lead to session hijacking, data theft, or defacement if successful.
OpenCVE Enrichment
EUVD