Impact
This vulnerability arises from improper neutralization of input, enabling stored XSS that can be used to execute arbitrary JavaScript in the context of site visitors. Attackers may embed malicious scripts that run whenever affected content is viewed, potentially leading to defacement, credential theft, or session hijacking.
Affected Systems
The flaw affects the WordPress SEO Bulk Editor plugin authored by Atanas Krachev in all releases up to and including version 1.1.0. Site administrators running this WordPress plugin without updating beyond 1.1.0 are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is stored XSS, so an attacker must be able to submit data via the plugin interface and that data must later be rendered on a page. If exploitation occurs, it could allow arbitrary scripts to run in the browsers of other visitors, with potential for defacement or data theft. The vulnerability is not yet listed in CISA KEV.
OpenCVE Enrichment
EUVD