Impact
Improper neutralization of user‑supplied data during web page generation enables a stored cross‑site scripting (XSS) flaw in the WordPress Icons Enricher plugin. An attacker who can submit content through the plugin interface can embed malicious JavaScript that will be executed in the browsers of any user who views the affected pages. The vulnerability does not directly affect the core WordPress installation, but it can lead to session hijacking, defacement, or theft of sensitive information from the user's perspective.
Affected Systems
The flaw affects the Icons Enricher plugin for WordPress, version 1.0.8 and all earlier releases. The plugin is developed by copist and the vulnerability is present in every release up through v1.0.8, with no patch included in those versions.
Risk and Exploitability
The flaw has a CVSS score of 6.5, indicating moderate severity. The EPSS score is less than 1 %, suggesting current exploitation activity is low. It is not listed in the CISA KEV catalog. The likely attack vector is a remote web interface, where the attacker submits malicious input that is later rendered by the page. Because it is a stored XSS, the payload persists until the content is removed, and it can affect any visitor who loads the compromised content, including privileged users.
OpenCVE Enrichment
EUVD