Impact
Improper Neutralization of Input During Web Page Generation allows an attacker to inject malicious script that is stored by the Dynamic Conditions plugin and executed in the browsers of users who view affected pages, enabling theft of session data or other client‑side attacks.
Affected Systems
The vulnerability affects the WordPress Dynamic Conditions plugin from rtowebsites, specifically all releases through version 1.7.4 installed on any WordPress site.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests exploitation is currently rare and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via any input field provided by the plugin that is not properly sanitized and then persisted, allowing an attacker to embed script that later runs when other users visit the affected page.
OpenCVE Enrichment
EUVD