Impact
Posts Footer Manager for WordPress has a stored cross‑site scripting flaw. Untrusted data entered via the plugin’s input fields is rendered in the footer for all site visitors without proper neutralization. An attacker who can inject malicious JavaScript can cause arbitrary code execution in the context of a visitor’s browser, potentially leading to session hijacking, credential theft, or site defacement.
Affected Systems
This vulnerability affects the Data443 Risk Mitigation, Inc. Posts Footer Manager plugin for WordPress versions up to and including 2.1.0.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low exploitation likelihood at present, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely an authenticated administrator who can submit content to the plugin’s footer or a remote attacker who can interact with the exposed input area; because the flaw is stored, exploitation requires the victim to view the affected footer.
OpenCVE Enrichment
EUVD