Impact
This vulnerability is a stored or reflected Cross Site Scripting flaw that permits an attacker to inject malicious JavaScript via a contributor field in the Elizaibots WordPress plugin. If exploited, malicious code runs in the context of a site visitor or authenticated user, potentially enabling session hijack, data theft, or defacement.
Affected Systems
WordPress installations that use the Elizaibots plugin from the author liseperu with a version of 1.0.2 or earlier are affected. No specific WordPress or operating system versions are listed, so any site with the vulnerable plugin is considered at risk.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as moderate severity. The EPSS score of < 1% indicates a very low probability of current exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is through the plugin’s contributor interface, a path that may be accessible without authentication; this inference is based on the description and typical WordPress plugin behavior.
OpenCVE Enrichment