Impact
The vulnerability is an improper neutralization of input during web page generation, which allows stored cross‑site scripting. Malicious JavaScript can be injected into the plugin’s output and executed in the context of visitors or administrators, enabling cookie theft, session hijacking, or defacement. The weakness is cataloged as CWE‑79.
Affected Systems
WordPress Video Embed Optimizer plugin by vendor fdfranklin06 is affected for all releases through version 1.0.0. No subsequent versions are listed in the available data.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to supply a crafted embed code or similar input that is stored and later rendered by the plugin. As a stored XSS, the exploitation path is indirect but poses a significant risk if a site visitor or administrator views the malicious content.
OpenCVE Enrichment
EUVD