Impact
The vulnerability is a stored cross-site scripting flaw that allows malicious scripts to be stored in the database and executed when visitors load the affected WordPress site. This can lead to cookie theft, session hijacking, defacement or the delivery of malware, compromising the confidentiality, integrity, and availability of the site’s content for all users.
Affected Systems
The flaw exists in the Scroll Top Advanced plugin (nasir179125) for WordPress, affecting all releases up to and including version 2.5. Users running older or current versions below 2.5 are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to inject malicious code through the plugin’s input fields, likely via the administration interface; successful exploitation would enable persistence of the malicious payload in the site’s content.
OpenCVE Enrichment
EUVD