Impact
The Simple Photo Sphere WordPress plugin contains an improper neutralization vulnerability that allows attackers to store arbitrary JavaScript code in the web page output. The flaw, classified as XSS, permits execution of attacker‑supplied scripts when any user accesses the affected content, potentially leading to theft of session data, defacement, or other client‑side compromises.
Affected Systems
The flaw affects all installations of snagysandor’s Simple Photo Sphere plugin with a version number up to and including 0.0.10. Any WordPress site that has this plugin installed in those version ranges is vulnerable.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is considered moderate‑high severity, yet the EPSS score of less than 1 percent suggests a low likelihood of exploitation. The issue is not listed in the CISA KEV catalog. The attack vector is inferred to be through any user entry point that allows administrative or content contributors to submit data handled by the plugin, which is then rendered without sanitization. Successful exploitation would result in the execution of stored scripts in the context of other users’ browsers.
OpenCVE Enrichment
EUVD