Impact
The vulnerability is an improper neutralization of input during web page generation in the Legacy ePlayer plugin, allowing attackers to store malicious scripts that will run in any browser that views the affected content. Such stored XSS enables session hijacking, credential theft, or defacement of the site, and the flaw is identified as CWE-79.
Affected Systems
Brian:Legacy ePlayer sportspress-tv plugin, versions from the earliest available through 0.9.9, is affected. Site owners using any of those versions should check and upgrade to a newer release.
Risk and Exploitability
The CVSS score of 6.5 places this issue in the medium severity range, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Because it is stored XSS, an attacker with normal content‑submission privileges can embed scripts that execute in the browsers of all visitors who view the injected content, creating high damage potential if the flaw is exploited.
OpenCVE Enrichment
EUVD