Impact
The VK All in One Expansion Unit plugin for WordPress is vulnerable to stored cross‑site scripting via the ‘vkExUnit_sns_title’ parameter in all versions up to and including 9.112.3 due to insufficient input sanitization and output escaping. Authenticated attackers with Contributor‑level access and higher can inject arbitrary scripts into this field, which are then stored and executed in the browser of any visitor to the affected page. This flaw permits the attacker to run client‑side code on the site.
Affected Systems
All installations of the VK All in One Expansion Unit WordPress plugin distributed by kurudrive, version 9.112.3 or earlier, on any WordPress site where the plugin is active.
Risk and Exploitability
With a CVSS score of 6.4 the vulnerability is of moderate severity. Its EPSS score is reported as less than 1 percent, indicating a very low probability of exploitation in the wild, and it is not currently listed in the CISA KEV catalog. The attack path requires the attacker to be authenticated with Contributor‑level or higher privileges and to have permission to edit SNS titles within the plugin. After privilege gain, the attacker can inject malicious scripts that will run whenever a user accesses the affected page.
OpenCVE Enrichment