Impact
The Stencies WordPress plugin contains an improper neutralization of input during web page generation, allowing a reflected cross‑site scripting flaw. This means that arbitrary JavaScript can be executed in the victim’s browser when the reflected input appears on a page.
Affected Systems
Stencies WordPress plugins with version numbers up to and including 0.58 are affected. All site installations using these plugin versions are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies this vulnerability as high severity, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit this flaw remotely by crafting a malicious URL or embedding unsanitized user input that is reflected by the plugin into web pages accessed by site visitors; no authentication is required. The likely attack vector is remote, web-based exploitation via a crafted URL or user input, which is inferred from the nature of reflected XSS.
OpenCVE Enrichment
EUVD