Impact
The IndieWeb plugin for WordPress is vulnerable to stored cross‑site scripting due to insufficient input sanitization and output escaping of the Telephone parameter. This flaw allows authenticated attackers with author level access or higher to inject arbitrary scripts into pages that will execute for any user who views the affected page.
Affected Systems
IndieWeb plugin for WordPress, all releases up to and including version 4.0.5.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, indicating medium severity, and an EPSS score of less than 1%, suggesting a low probability of exploitation. It is not listed in CISA’s KEV catalog. The attack requires the attacker to be logged into the site with author privileges or higher, and then supply a malicious payload via the Telephone field; the script will persist in the stored content and execute when an end‑user visits the page. Based on the description, the relevant attack vector is authenticated, not remote unauthenticated.
OpenCVE Enrichment