Impact
The Think201 Data Dash plugin contains an improper neutralization of input during web page generation, allowing attackers to store malicious scripts. This stored XSS flaw permits execution of arbitrary JavaScript in other users' browsers, potentially enabling credential theft, session hijacking, or defacement. The weakness is identified as CWE-79, an input validation error that allows script injection.
Affected Systems
WordPress sites that include the Data Dash plugin version 1.2.3 or earlier, covering all releases of Think201's Data Dash plugin up to that version.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests low likelihood of exploitation and the vulnerability is not listed in CISA's KEV catalog. Attackers would need access to a form where Data Dash accepts user input—such as plugin settings or data entry screens—which can be exploited by a malicious user or by compromising an administrator account. The impact is confined to the victim’s browser context, but could lead to credential compromise or defacement. The likely attack vector is inferred from the stored XSS nature and the plugin’s input handling capabilities.
OpenCVE Enrichment
EUVD