Impact
The vulnerability is an improper neutralization of input during webpage generation in the Skill Bar plugin for WordPress. It allows stored cross‑site scripting, where an attacker can inject malicious JavaScript into the plugin’s output that will be executed in the browser of any user visiting the affected site. This can lead to defacement, theft of session cookies, or execution of arbitrary client‑side code.
Affected Systems
This flaw affects the WordPress Skill Bar plugin developed by Themepoints, versions from any unreleased version (n/a) through version 1.2. Sites running any of these versions are susceptible if the plugin is enabled.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while an EPSS score of less than 1% suggests exploitation is unlikely at the moment. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker using the plugin’s configuration or content entry interface to store malicious payloads that are later rendered to browsers. An attacker would need access to an interface that can persist data; any authenticated or unauthenticated user with such access could compromise other site visitors.
OpenCVE Enrichment
EUVD