Impact
The vulnerability allows a stored cross‑site scripting (XSS) via the Highlight Color setting in the Just Highlight WordPress plugin. The flaw arises from inadequate input sanitization and output escaping, enabling an attacker to inject arbitrary JavaScript that runs when any user visits the plugin’s settings page. The impact is the potential compromise of affected users’ browsers, which could lead to session hijacking or other client‑side attacks. The weakness is classified as CWE‑79, a classic XSS scenario.
Affected Systems
WordPress sites running the Just Highlight plugin version 1.0.3 or earlier. The plugin is identified by the vendor sigalitam under the product Just Highlight. No later versions are affected.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity, but the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in CISA KEV, implying no known large‑scale exploitation. Attackers must be authenticated with administrator‑level or higher privileges and must modify the Highlight Color field. Once injected, the malicious script will run for every visitor who opens the settings page.
OpenCVE Enrichment