Impact
The Forex Calculators plugin for WordPress contains an improper neutralization of input vulnerability that allows an attacker to inject JavaScript that the plugin will persist and output to the web page. This stored cross‑site scripting flaw can execute arbitrary JavaScript within the context of rendered pages. The weakness is a classic text‑input handling bug classified as CWE‑79.
Affected Systems
Levan Tarbor’s WordPress Forex Calculators plugin versions up to and including 1.3.6 are affected. The vulnerability applies to every installation of this plugin that uses those or earlier versions.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score of less than 1% implies that the exploit is rarely observed in the wild. The vulnerability is not listed in the CISA KEV catalog, so no known active supply‑chain compromise is reported. An attacker would need to identify a site running the vulnerable plugin, then craft a malicious input that the plugin stores and later renders. Because the stored payload is executed in the context of the website, any user who visits the affected page could be impacted.
OpenCVE Enrichment
EUVD