Impact
This vulnerability is an improper neutralization of input during web page generation, resulting in a stored cross‑site scripting (XSS) flaw in the Smart Custom Fields plugin. An attacker who can insert malicious script data that is persisted by the plugin could cause browsers of any authenticated or unauthenticated user to execute arbitrary JavaScript when viewing affected pages. The flaw originates from the plugin’s failure to validate or encode user‑supplied fields before rendering, a weakness cataloged as CWE‑79.
Affected Systems
The affected product is the WordPress Smart Custom Fields plugin by Takashi Kitajima. All versions up to and including 5.0.0 are vulnerable. No specific sub‑version or patchlevel information is provided beyond the maximum affected version.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity. EPSS is below 1%, implying a low probability of exploitation in the immediate term, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to discover or be granted the ability to inject data into the plugin’s fields, typically via an authenticated user or a public data entry point exposed by the plugin. Once injected, the script executes in any browser that loads the compromised content.
OpenCVE Enrichment
EUVD