Impact
The Octrace Support plugin contains a stored cross‑site scripting flaw where user input is not properly neutralized before rendering. An attacker can submit malicious content that is stored and later presented to other visitors, causing arbitrary JavaScript execution in the browsers of those users.
Affected Systems
The Octrace WordPress HelpDesk & Support Ticket System Plugin – Octrace Support, all releases up to and including version 1.2.7.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of less than 1 % shows a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The attack requires submission of malicious input that will be stored and later displayed to other users; it is a stored XSS flaw. Based on the description, it is inferred that the flaw can be triggered via the plugin’s ticket or content submission interfaces.
OpenCVE Enrichment
EUVD