Impact
The Powerful Auto Chat plugin for WordPress fails to sanitize user input properly, allowing attackers to store malicious scripts that are later rendered in the browser. This stored XSS can execute arbitrary client‑side code in the context of any visitor who views the affected page, potentially leading to defacement, credential theft, or session hijacking. The weakness is a classic input validation flaw (CWE‑79).
Affected Systems
The vulnerability applies to the "Felipe Peixoto Powerful Auto Chat" WordPress plugin in all releases up to and including version 1.9.8. No specific WordPress core or other plugins are listed as affected.
Risk and Exploitability
The CVSS score of 6.5 places the flaw in the “medium” severity range, while the EPSS score of less than 1% indicates a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely exploitation path involves an attacker submitting a malicious payload through a legitimate plugin input field, which is then stored in the database and served to users. Although the attack does not provide remote code execution on the server, the impact on the client side can compromise users and reduce the integrity of the site’s content.
OpenCVE Enrichment
EUVD