Impact
This weakness is a Cross‑Site Request Forgery that couples with a stored cross‑site scripting vulnerability. An attacker can trick an authenticated user into sending a forged request that injects malicious script into a post status. The injected code subsequently executes whenever the compromised content is displayed, leading to session hijacking, credential theft or defacement. The core weakness is identified as CWE‑352.
Affected Systems
WordPress installations that use the page‑carbajal Custom Post Status plugin, version 1.1.0 or earlier, are affected. These sites typically host the plugin via the WordPress plugin repository.
Risk and Exploitability
The CVSS score of 7.1 denotes a high‑severity flaw, whereas the EPSS score of less than 1 % indicates a very low probability of widespread exploitation at present. The flaw is not listed in CISA’s KEV catalog. Exploitation requires an authenticated session with sufficient privileges to modify content, and an attacker would most likely employ social‑engineering techniques to get the victim to visit a crafted URL or submit a malicious form.
OpenCVE Enrichment