Impact
The TWW Protein Calculator plugin for WordPress allows an attacker with administrator permissions to store a malicious script inside the ‘Header’ setting. Because the input is not properly sanitized or escaped, the stored script is executed in the browsers of all users who view the affected page, enabling the attacker to run arbitrary client‑side JavaScript.
Affected Systems
TWW Protein Calculator by The Wellness Way, available as a WordPress plugin, is affected. All versions up to and including 1.0.24 are vulnerable, with the issue manifesting on multi‑site WordPress sites where unfiltered_html has been disabled.
Risk and Exploitability
The CVSS score of 4.4 classifies the vulnerability as moderate. The EPSS score of less than 1% indicates a very low likelihood of exploitation at the time of this advisory, and it is not listed in the CISA KEV catalog. The vulnerability requires an authenticated attacker who holds administrator rights; once the malicious payload is stored, it runs for any visitor of the affected page, meaning the impact extends to all users who view that page.
OpenCVE Enrichment