Impact
The weakness is a CSRF flaw that allows an attacker to inject a stored XSS payload via the Hide Real Download Path plugin. A forged request can store malicious script in the plugin’s data, which will execute in the browsers of any visitor to the affected site. The impact is the potential compromise of confidentiality and integrity of site content, user session hijacking, and defacement. The vulnerability is formally identified as CWE‑352.
Affected Systems
WordPress installations that use the Deepak S Hide Real Download Path plugin, any version up to and including 1.6.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high risk, but the EPSS score of less than 1% suggests exploitation is rare at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would require an attacker to craft a forgery request that the user’s browser submits with a valid session cookie, so it is most likely to target sites where users have administrative access or where the plugin accepts unsanitised input from authenticated sessions.
OpenCVE Enrichment
EUVD