Impact
Improper neutralization of input during web page generation enables stored cross‑site scripting in the JK Html To Pdf plugin. This vulnerability is classified as CWE-79 and allows an attacker to inject arbitrary scripts into stored content.
Affected Systems
All WordPress installations that use the JK Html To Pdf plugin version 1.0.0 or earlier are affected. The vulnerability covers the entire product range from the first release up to, and including, 1.0.0.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium-to-high severity impact. The EPSS score is less than 1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw via CSRF to store malicious content that may later be accessed by site users.
OpenCVE Enrichment
EUVD