Impact
The weichuncai WordPress plugin contains a missing or incorrect nonce validation in the sm‑options.php page, creating a Cross‑Site Request Forgery vulnerability. An unauthenticated attacker can forge a request that updates the plugin settings with arbitrary JavaScript payloads. Because the plugin stores this input and embeds it in page output, the malicious script is executed whenever a visitor loads the site, resulting in stored cross‑site scripting.
Affected Systems
All installations of the weichuncai plugin produced by lmyoaoa, version 1.5 and older, are affected. Administrators using these legacy versions are at risk until they upgrade the plugin to a version that implements proper nonce checks.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score of <1% suggests a very low probability of exploitation at this time. Attackers must convince a site administrator to click a crafted link or otherwise submit a forged request, a scenario that can arise in standard phishing. The vulnerability is not listed in the CISA KEV catalog, meaning no documented active exploits are currently known. Despite the low exploitation likelihood, the potential for persistent malicious script injection warrants immediate remediation.
OpenCVE Enrichment
EUVD