Impact
This vulnerability allows attackers to inject and store malicious JavaScript code within the WP Github plugin data. The stored XSS flaw enables arbitrary scripts to run in the context of the site for any user who views affected pages, potentially leading to session hijacking, credential theft, defacement, or the delivery of malware. The weakness is identified as a classic client‑side injection flaw (CWE‑79).
Affected Systems
The flaw exists in the seinoxygen WP Github plugin for WordPress versions up through 1.3.3. Any WordPress site using this plugin version is susceptible, regardless of other security controls. The affected product is identified as the WP Github plugin, with a version range from the initial release up to and including 1.3.3.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating a moderate level of severity. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at present, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector typically involves privileged users submitting or modifying content that is then rendered via the plugin, or an attacker who can inject content into the plugin’s data store. If an attacker succeeds, they can execute arbitrary JavaScript on any visitor’s browser when that content is displayed.
OpenCVE Enrichment
EUVD