Impact
This vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to inject malicious script into the track‑everything plugin’s storage. By crafting a forged request that the victim’s browser automatically submits, an attacker can store arbitrary code that will execute in the context of every subsequent user who views the vulnerable element. The ability to run user‑controlled scripts can lead to session hijacking, defacement, or further exploitation of the site.
Affected Systems
The issue affects the ethoseo Track Everything WordPress plugin version 2.0.1 and all earlier releases. Any WordPress site deploying one of these versions and not applying the patch is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 reflects a moderate to high risk due to the combined impact of CSRF and stored XSS. The EPSS score of less than 1% indicates a low probability of exploitation at this time, and the vulnerability is not yet listed in the CISA KEV catalog. Nonetheless, because the flaw can be triggered by a forged request from a third‑party site without requiring special privileges, the attack vectors available to an adversary are significant for sites that do not enforce strict CSRF protection.
OpenCVE Enrichment
EUVD