Impact
The Zweb Social Mobile plugin for WordPress is vulnerable to stored cross‑site scripting through several admin‑only parameters. An attacker who can authenticate as an administrator can submit arbitrary JavaScript that is then saved and rendered on pages accessed by visitors, causing the script to execute whenever those pages are viewed.
Affected Systems
This flaw affects all installations of the Zweb Social Mobile plugin up to and including version 1.0.0 when deployed on WordPress multisite setups that have the unfiltered_html capability disabled. Only users with administrator privileges who have access to the plugin’s configuration pages can perform the injection.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires that an attacker first gain administrative access to the site; once the malicious script is stored, it remains active until the plugin is updated or the content is removed.
OpenCVE Enrichment