Impact
The vulnerability is a CSRF flaw in the Purge Varnish Cache WordPress plugin that lets an attacker trick an authenticated administrator into executing unintended actions. By sending a crafted request, the attacker can cause the plugin to store malicious script code, leading to stored XSS. The flaw, classified as CWE-352, exposes the site to integrity and confidentiality compromises.
Affected Systems
The Purge Varnish Cache plugin delivered by Dsingh, version 2.6 and earlier, is affected. Versions before 2.6 are also potentially vulnerable as the change set does not specify a lower bound.
Risk and Exploitability
The CVSS score is 7.1, indicating high severity, while the EPSS score is below 1 % and the vulnerability is not listed in KEV. The likely attack vector is CSRF, where a user who is already authenticated is lured to a malicious URL that issues a purge request, thereby injecting stored XSS into the site. Although exploitation is possible, its probability is currently low according to EPSS, but the impact warrants prompt remediation.
OpenCVE Enrichment
EUVD