Impact
An improper neutralization of input during web page generation has been found in the REAL WordPress Sidebar plugin. The flaw allows a malicious user to store script code that is later rendered in the sidebar area, enabling arbitrary client‑side script execution.
Affected Systems
The vulnerability affects the REAL WordPress Sidebar plug‑in developed by martin_ziegert, identified as genre “drag‑and‑drop‑custom‑sidebar.” Any installation running version 0.1 or earlier is impacted; updates beyond 0.1 may contain a fix, but this is not confirmed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact while the EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of exploitation at present. The likely attack path, which is inferred from the description, involves an authenticated user with permission to edit sidebar content inserting a script payload; this payload is stored in the database and then served to all visitors when the sidebar is displayed. Because the flaw is stored, it remains in the database until the plugin is removed or site content is cleaned.
OpenCVE Enrichment
EUVD