Impact
The Biltorvet Dealer Tools plugin for WordPress includes a stored cross‑site scripting flaw caused by improper neutralization of input during page generation. This weakness, identified as CWE‑79, allows an attacker to embed malicious JavaScript that is served to any visitor of a compromised page, potentially leading to credential theft, session hijacking, or site defacement.
Affected Systems
All versions of the Auto IT Biltorvet Dealer Tools WordPress plugin up to and including 1.0.22 are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at present. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to submit malicious input through the plugin’s storage mechanisms, which then becomes part of the page viewed by other users. Remote delivery of the payload is possible via the WordPress administration interface or any user input fields that the plugin persists; physical or remote access to the WordPress site is required to inject the payload. Once injected, the script executes in any visitor’s browser.
OpenCVE Enrichment
EUVD