Impact
The Simple User Meta Editor plugin’s user meta value field lacks sufficient input sanitization and output escaping, leading to stored cross‑site scripting. An attacker with administrator privileges can inject malicious scripts that execute whenever any user visits a page containing the injected meta value. This enables the attacker to run arbitrary code in the victim’s browser, potentially leading to session hijacking, cookie theft, or malicious content injection.
Affected Systems
The vulnerability exists in all versions of the Simple User Meta Editor plugin up to and including 1.0.0. It only applies to WordPress multi‑site installations where the unfiltered_html capability is disabled, and is written by the vendor anjan011.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity, whereas the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because an attacker must first have administrator‑level access to inject the script, the attack vector is authenticated. If such privileged access is available, the impact can be significant for all users who will view affected pages.
OpenCVE Enrichment