Impact
The plugin contains an input field that is incorporated into web pages without proper neutralization, allowing an attacker to inject malicious JavaScript. Because the flaw is stored, injected code persists across sessions and can affect any user who views the affected page.
Affected Systems
The vulnerability exists in the sw.galati iframe to embed plugin from the earliest version through 1.2. Any WordPress installation that includes the plugin and uses its default configuration is impacted.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate risk, while an EPSS score of less than 1% suggests that exploitation is unlikely but still possible. The vulnerability is not listed in CISA KEV. Attackers would need to supply malicious input via the web interface or a crafted request that the plugin accepts, typically from an administrative user or an unauthenticated user with write access to the plugin’s data. Successful exploitation would allow persistent client‑side code to run in the browsers of site visitors, enabling session hijacking, defacement, or data theft.
OpenCVE Enrichment
EUVD