Impact
The Obaid Hossain jQuery TwentyTwenty plug‑in for WordPress contains an improper neutralization of user‑supplied input during web page generation. This flaw allows malicious scripts to be stored in the plugin’s content and subsequently served to visitors, enabling arbitrary code execution within the victim’s browser.
Affected Systems
Any WordPress installation that includes the Obaid Hossain jQuery TwentyTwenty plug‑in version 1.0 or earlier is affected.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation. The flaw is not listed in CISA KEV. An attacker would need to inject a malicious payload through the plug‑in’s input controls that is stored in the database and later rendered in a page viewed by users. Without remediation, affected sites could expose visitors to unintended script execution.
OpenCVE Enrichment
EUVD