Impact
The SmugMug Embed WordPress plugin up to version 3.13 lacks authentication and CSRF checks on an AJAX action that stores gallery data and fails to sanitise or escape that data before outputting it. This allows any unauthenticated user to inject arbitrary JavaScript that is stored and executed when an administrator later views the plugin’s settings screen. The stored script runs with the privileges of the logged‑in administrator, enabling defacement, credential theft, or further exploitation of the site. The impact therefore includes a compromise of administrator confidentiality, integrity, and availability of the WordPress dashboard.
Affected Systems
Products affected are the SmugMug Embed WordPress plugin from the vendor listed as Unknown:SmugMug Embed, versions through and including 3.13. No other variant or version is specified in the available data.
Risk and Exploitability
The vulnerability is a classic stored XSS flaw, which is high‑impact when the administrator’s browser processes the stored script. Attackers can exploit the flaw by sending a crafted AJAX request without authentication; the lack of CSRF protections means the request can be triggered from any client, including untrusted networks. The CVSS score is 8.8, the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating that while it can be exploited, it is not known to have been widely used in the wild. Nevertheless, the potential for severe impact warrants immediate attention.
OpenCVE Enrichment