Impact
This vulnerability is a Stored XSS flaw caused by improper neutralization of user‑supplied input during web page generation in the Robert Responsive Flickr Slideshow WordPress plugin. An attacker can embed malicious script that will be executed in the browsers of any visitor who views a page containing the injected data.
Affected Systems
The issue affects the Responsive Flickr Slideshow WordPress plugin for all versions up to and including 2.6.0. Users running 2.6.0 or earlier versions are potentially exposed.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of active exploitation at present. The flaw is not listed in the CISA KEV catalog, further implying limited real‑world usage. Based on the description, the likely attack vector is stored input that later renders as script in web pages; an attacker would need to create or modify a slideshow item containing the payload. After the payload is stored, any visitor to the site would execute the embedded code.
OpenCVE Enrichment
EUVD