Impact
Improper neutralization of user input in the Include Mastodon Feed plugin allows DOM‑based XSS, enabling attackers to inject arbitrary JavaScript into webpages generated by the plugin. The flaw permits execution of client‑side scripts when a user loads a page that includes a Mastodon feed, potentially allowing harmful actions such as defacement or other malicious behaviors, based on the nature of XSS.
Affected Systems
Wolfgang’s Include Mastodon Feed WordPress plugin is affected in all releases up to and including version 1.9.9. Any WordPress site that has installed this plugin at or below that version is vulnerable, regardless of site configuration.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity level. The EPSS score of less than 1% indicates that, according to current data, exploitation is unlikely, and the vulnerability is not listed in CISA KEV. The flaw is client‑side; an attacker would need to craft a link or embed malicious content that a site visitor loads, causing the victim’s browser to execute injected JavaScript within the context of the site. The malicious script runs with the privileges of the page, making it possible to alter page content or perform other client‑side actions.
OpenCVE Enrichment
EUVD