Impact
The vulnerability is a CSRF flaw in the WordPress Behance Portfolio Manager plugin that allows a malicious actor to submit forged requests from a user's browser, resulting in injected JavaScript that is stored and later executed by other visitors. This stored XSS can compromise confidentiality and integrity, and the weakness is identified as CWE-352.
Affected Systems
The flaw impacts all installations of the eleopard Behance Portfolio Manager plugin on WordPress sites running version 1.7.5 or earlier, including all previous releases. Site owners using these versions are considered vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates medium to high severity, while the EPSS score of < 1% suggests the likelihood of real-world exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Because CSRF typically requires a victim to be authenticated and to trigger the malicious request, the attack vector is likely user-based and would involve a malicious link or form that the victim clicks or submits. The attacker can leverage the stored XSS to execute arbitrary JavaScript in the context of visitors to the affected WordPress site.
OpenCVE Enrichment