Impact
The Include Fussball.de Widgets plugin allows an authenticated user with Contributor privileges or higher to store malicious scripts in the 'api' and 'type' fields. These scripts are rendered without proper escaping, leading to stored Cross‑Site Scripting that can run whenever an affected page is viewed. The flaw is a classic input validation and output escaping weakness (CWE‑79) and could be used for session hijacking, defacement, or distributing malware.
Affected Systems
The vulnerability is present in all supported releases of the mheob Include Fussball.de Widgets WordPress plugin up to and including version 4.0.0. No specific WordPress core versions are mentioned, so any site running the plugin on those versions is affected.
Risk and Exploitability
The CVSS base score of 6.4 indicates a moderate risk, with an EPSS of less than 1 % showing a very low, but non‑zero, probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. The likely attack vector requires authentication; an attacker who can edit content via the plugin or manipulate the 'api' and 'type' parameters can inject payloads that persist in the database and execute on subsequent page views by any visitor.
OpenCVE Enrichment