Impact
The vulnerable plugin accepts an unescaped redirect parameter that can be stored and later rendered in the browser. An attacker with subscriber‑level or higher privileges can inject scripts into the site’s stored data. When a site visitor loads the affected page, the malicious code runs in the visitor’s browser, potentially stealing session cookies or performing other actions under the visitor’s context.
Affected Systems
WordPress plugin Inactive Logout (j_3rk:Inactive Logout) and any older releases – all versions up to and including 3.5.5. The issue is specific to that plugin only, and no other WordPress components are affected in the CVE scope.
Risk and Exploitability
The CVSS score of 6.4 classifies the flaw as medium severity, and the EPSS score of less than 1% indicates a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker must first be authenticated with at least subscriber permissions to manipulate the redirect parameter, after which a stored cross‑site scripting attack can be delivered to any user who views the injected content. Even with the low probability, the medium severity and the compatibility with normal user access make this a relevant risk for sites that use this plugin.
OpenCVE Enrichment