Impact
The vulnerability is a stored cross‑site scripting flaw in the Thai Lottery Widget plugin. Unsanitized width and height attributes in the thailottery shortcode let an attacker inject arbitrary JavaScript that is saved to the database and executed whenever a page containing the shortcode is viewed.
Affected Systems
WordPress sites running Thai Lottery Widget 2.5 or earlier are affected. The problem exists in all cached instances of the plugin up to and including version 2.5.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the issue is not listed in CISA’s KEV catalog. Attackers need authenticated Contributor‑level access to an affected site to inject the script, so an insider or compromised account is required. The attack vector is internal; compromise of the site’s administration gives the attacker the means to place malicious scripts that will run in the browsers of all visitors to the injected page.
OpenCVE Enrichment