Impact
The Foundation Columns plugin by tormorten fails to properly neutralize user input when generating web page content, which allows a stored cross‑site scripting (XSS) vulnerability (CWE‑79). An attacker who can insert content through the plugin’s user interface can store malicious JavaScript in the WordPress database. When a visitor loads the affected page, the script is executed in the victim’s browser, potentially exposing the user to unauthorized actions executed by the injected code.
Affected Systems
WordPress installations that utilize the Foundation Columns plugin version 0.8 or earlier. This includes any site running the tormorten Foundation Columns package at or below the specified version without applying a patch from the vendor.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests that widespread exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the plugin’s content editing endpoint, where an attacker with permission to modify content can inject malicious scripts that persist in the database and trigger on page load for all site visitors.
OpenCVE Enrichment
EUVD