Impact
The WPShapere Lite plugin does not validate CSRF tokens on requests that alter site data, allowing an attacker to forge a request that stores malicious JavaScript in the site’s content. When a victim later views the affected page, the script executes in their browser, enabling session hijacking, data theft, or defacement. This flaw combines CSRF with stored XSS, making it especially dangerous because it can be triggered without any manual interaction from the end user after the initial CSRF trick.
Affected Systems
AcmeeDesign WPShapere – WordPress admin theme is affected for all releases up to and including version 1.4.1. Users on these versions should assume the vulnerability is present.
Risk and Exploitability
The CVSS score of 7.1 indicates a high level of severity, while the EPSS score of less than 1 % suggests the vulnerability is currently rarely exploited in the wild. It is not listed in the CISA KEV catalog. Exploitation requires an authenticated session or the ability to trick an administrative user into submitting a forged request, so the attack vector is likely authenticated or social‑engineering based. Once the CSRF request is performed, the injected JavaScript is permanently stored and will affect every visitor of the compromised page.
OpenCVE Enrichment
EUVD