Impact
The Playerzbr plugin for WordPress contains a stored cross‑site scripting vulnerability caused by insufficient input sanitization and output escaping of the 'urlmeta' post meta field. An authenticated user with contributor level or higher can inject arbitrary scripts that are saved in the database and executed whenever another user views the affected page. This stored XSS can lead to defacement, theft of session cookies, and execution of malicious code, compromising the confidentiality and integrity of site visitors, and it maps to CWE‑79.
Affected Systems
WordPress sites running the Playerzbr plugin version 1.6 or earlier, developed by the vendor pedrolaxe, are affected. All versions up to and including 1.6 use the vulnerable 'urlmeta' field.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% shows a very low yet non‑zero likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access with contributor or higher privileges, enabling the attacker to edit a post and store a malicious payload in the 'urlmeta' field via the WordPress admin interface.
OpenCVE Enrichment