Impact
Improper neutralization of input during web page generation allows a stored cross‑site scripting (XSS) flaw in the SetMore Theme – Custom Post Types plugin. An attacker may inject malicious script that the plugin will embed in generated pages, enabling attacks such as credential theft, session hijacking, or defacement when an authenticated user views the affected content.
Affected Systems
Setmore’s SetMore Theme – Custom Post Types plugin, versions up to and including 1.1.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating moderate severity. The EPSS score is reported as below 1 %, indicating a low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. The likely attack vector is via the plugin’s content entry flow, where unsanitized user input can be stored and later rendered to visitors. If exploited, attackers could achieve execution of arbitrary JavaScript in the context of legitimate site visitors, potentially compromising user data or weaponizing the site for phishing.
OpenCVE Enrichment
EUVD