Impact
A flaw in the Current Age Plugin allows a user to forge requests that the plugin does not properly verify, leading to the injection of a script that is stored in the database. Once stored, the script executes whenever the page is rendered, letting an attacker steal cookies, deface content, or hijack sessions, thereby compromising user accounts and site integrity.
Affected Systems
WP CMS Ninja Current Age Plugin versions 1.6 and earlier are affected. The vulnerability is present in all releases of the plugin in that range, regardless of WordPress core version.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity impact. The EPSS score of less than 1% implies that current exploitation is rare, and the vulnerability is not listed in CISA’s KEV catalog. An attacker can target the plugin by sending a crafted HTTP request to the site where the malicious script is stored, undermining confidentiality and integrity of data. The attack requires the target user to be authenticated or the site to be running an exposed interface that accepts the forged request.
OpenCVE Enrichment
EUVD