Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper input neutralization in the SingSong WordPress plugin. When malicious data is saved through the plugin’s interfaces, it is rendered later without proper escaping, enabling an attacker to inject arbitrary JavaScript that will execute in the browser context of any user who views the affected content. This can result in defacement, session hijacking, credential theft, or the delivery of phishing payloads. The weakness is the Classic CWE‑79 type of injection.
Affected Systems
Any WordPress installation that has been deployed with the SingSong plugin version 1.2 or earlier. The vendor responsible for the vulnerability is roya khosravi, and the affected product is SingSong.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high risk level. The EPSS score of less than 1% means that, historically, the probability of exploitation is quite low, and the vulnerability is not listed in the CISA KEV catalog. Attackers would most likely exploit this through a web interface, possibly requiring an authenticated content‑authoring or administrative account, but the injected script could run for any visitor that loads the poisoned content. Because the flaw resides in stored input rendering, the attack can be launched remotely via the WordPress site and does not require local code execution on the server.
OpenCVE Enrichment
EUVD