Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation that permits a stored cross‑site scripting attack in the Bytephp Arcade Ready WordPress plugin. An attacker can inject JavaScript that executes whenever a page generated by the plugin is viewed, potentially hijacking user sessions, defacing site content, or facilitating further exploitation.
Affected Systems
Bytephp Arcade Ready plugin for WordPress versions up to and including 1.1 are affected.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is considered moderate‑high severity. The EPSS score is below 1%, indicating a low likelihood of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Likely attack vectors involve submitting malicious payloads through plugin input fields or content areas, which become stored and rendered to other visitors. The risk is mitigated only by removing or sanitizing the vulnerable input, hence site owners are advised to act promptly.
OpenCVE Enrichment
EUVD