Impact
The vulnerability allows an attacker to inject malicious scripts that are stored in the plugin’s database and executed when any user views the affected page. This can lead to defacement, theft of session cookies, or the execution of arbitrary client‑side code. The weakness is a classic input–output mis‑handling flaw identified as CWE‑79.
Affected Systems
WordPress sites that include the CHR Designer Responsive jQuery Slider plugin version 1.1.1 or earlier are affected. The plugin is used on any site that has added the slider through the typical WordPress admin interface.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through the plugin’s data entry fields (e.g., slider description or custom code areas) that accept input without proper neutralization and are later output to the page.
OpenCVE Enrichment
EUVD