Impact
The Header and Footer Scripts plugin for WordPress contains a stored XSS flaw that is triggered through the _inpost_head_script parameter. Insufficient input sanitization and output escaping enable an attacker to store malicious JavaScript in the plugin's configuration, which is then rendered into every page that includes the script. This vulnerability allows the injection of arbitrary client‑side code that can execute in the context of any visitor to the affected page.
Affected Systems
WordPress sites that have installed the anand_kumar:Header and Footer Scripts plugin, in any version up to and including 2.3.0. The flaw is exploitable by any authenticated user with Contributor level or higher access on the site.
Risk and Exploitability
With a CVSS score of 6.4 the vulnerability is rated moderate. The EPSS score of less than 1% indicates a low probability that exploit code will be widely deployed at present. The flaw is not listed in the CISA KEV catalog. An attacker needs a valid Contributor+ account; once authenticated, they can inject script via the plugin’s configuration interface, causing that script to execute automatically for each user who views the processed page.
OpenCVE Enrichment