Impact
The Osiris Signature Banner WordPress plugin contains a missing nonce check that allows unauthenticated attackers to forge administrative requests. By submitting a crafted request, an attacker can change the plugin’s prepend_text setting to include arbitrary JavaScript, resulting in stored cross‑site scripting that will run in the browsers of any site visitor and can be used to steal credentials, deface content, or redirect users. of CWE‑352 – Cross‑Site Request Forgery.
Affected Systems
All installations of the Osiris Signature Banner plugin up to and including version 0.5 are vulnerable. Administrators using WordPress sites with this plugin should verify their plugin version and apply any available update.
Risk and Exploitability
The vulnerability receives a CVSS score of 6.1, indicating a medium severity impact. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no current widespread exploitation. The attack vector requires the attacker to coerce a site administrator into executing a forged request, such as clicking a malicious link. If successful, the resulting stored XSS provides persistent access to all visitors of the site.
OpenCVE Enrichment