Impact
The Content Mask WordPress plugin fails to sanitize or escape content submitted in posts before rendering it on the generated pages. A user with contributor level can inject malicious script into the post, which will then be executed in the browser of any user viewing or previewing that page. This stored cross‑site scripting allows the attacker to steal session cookies, hijack user accounts, deface content, or redirect users to phishing sites.
Affected Systems
WordPress sites using the Content Mask plugin, version 1.7.1 through 1.8.5.5. Any installation of these releases is vulnerable regardless of role‑based restriction settings.
Risk and Exploitability
The vulnerability can be exploited simply by submitting a post containing a malicious payload; no special network access or external interaction is required beyond having contributor privileges. The EPSS score is 0.00163, which indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. Nevertheless, the nature of stored XSS implies a high potential for exploitation on sites that are publicly accessible or used by many users. Sites that allow many contributors or lack strict content validation will be at the greatest risk. The CVSS score of 6.8 reflects a medium severity level.
OpenCVE Enrichment