Impact
The vulnerability is an improper neutralization of input during web page generation that results in a DOM‑based XSS flaw in the Able Player WordPress plugin. The flaw allows an attacker to inject crafted JavaScript into pages generated by the plugin, potentially running in the victim’s browser when the page is viewed.
Affected Systems
WordPress sites that have installed Damion Armentrout’s Able Player plugin with a version up through 1.0 are affected. No specific sub‑version indication is provided, so any instance of the plugin as of version 1.0 or earlier should be treated as vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1 % suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to load a page that includes the plugin’s output; the attack is client‑side and typically achieves defacement or phishing. No remote code execution or server‑side compromise is possible based on the provided description.
OpenCVE Enrichment
EUVD