Impact
The vulnerability is a CSRF flaw that allows an attacker to submit crafted requests that are executed by the WordPress site, leading to stored cross‑site scripting. An attacker can then inject arbitrary scripts that persist in the database and run in the browsers of site visitors, which can lead to credential theft or defacement.
Affected Systems
The affected product is the WordPress MSTW League Manager plugin developed by Mark O'Donnell. All releases from the first available version up to and including 2.10 are vulnerable. No specific sub‑versions are highlighted beyond the 2.10 upper bound.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. It is not listed in the CISA KEV catalog. Likely the attack vector is via the web interface of a WordPress site that has the plugin activated; the attacker needs only a crafted request sent from a victim’s browser.
OpenCVE Enrichment
EUVD