Impact
The extendyourweb HORIZONTAL SLIDER plugin contains a CSRF weakness that permits an attacker to store arbitrary script payloads. When a forged request is accepted by the plugin, the payload becomes part of the site’s content and is executed for any visitor who views that content. This stored XSS can be used for malicious actions such as phishing or cookie theft, and the flaw is identified as CWE‑352.
Affected Systems
WordPress sites that run the extendyourweb HORIZONTAL SLIDER plugin version 2.4 or earlier, regardless of their server environment, are affected.
Risk and Exploitability
The CVSS score of 7.1 assigns high severity. The EPSS score of less than 1% suggests a low likelihood of active exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation would typically require a CSRF attack, such as sending a specially crafted request to an authenticated user, to store malicious scripts. Once stored, the script runs for each visitor to the affected content, potentially allowing attackers to perform client-side attacks.
OpenCVE Enrichment
EUVD