Impact
The Social Media Engine plugin for WordPress stores data without properly neutralizing input, allowing a stored cross‑site scripting (XSS) vulnerability. When a malicious user or attacker injects script into fields that the plugin displays, the code executes in the browsers of visitors who load the affected content. This can lead to session hijacking, cookie theft, defacement of the site, and the execution of arbitrary client‑side actions that compromise user trust and confidentiality.
Affected Systems
WordPress installations that use the ThemesCraft.co Social Media Engine plugin version 1.0.2 or earlier. No other vendors or products are listed as affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating moderate severity. The EPSS score is reported as less than 1%, signaling a very low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves injecting malicious input via the plugin’s input fields, which may require authentication, although it is unknown whether public writable fields are exposed.
OpenCVE Enrichment
EUVD