Impact
Codexpert, Inc CoDesigner stores user‑supplied input without proper neutralization, allowing attacker‑supplied scripts to be persisted and executed when the content is rendered. This stored XSS can lead to session hijacking, credential theft, or the injection of malicious content into browsers that view the compromised data. The weakness is a classic improper input handling flaw, classified as CWE‑79.
Affected Systems
The vulnerability affects the CoDesigner WordPress plugin in all releases up to and including version 4.29. No exact sub‑version is listed beyond this ceiling, so any installation of CoDesigner 4.29 or earlier is potentially impacted.
Risk and Exploitability
The CVSS score of 5.9 places the flaw in the medium risk range. The EPSS score of less than one percent indicates a very low probability that the vulnerability will be actively exploited in the wild, and it is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Likely attackers would need the ability to inject content into the plugin’s storage area, such as via admin or content‑creation functions, to place the malicious payload. The stored nature of the exploit means it could affect all users who view the infected content.
OpenCVE Enrichment
EUVD