Impact
Improper neutralization of input during web page generation allows stored cross‑site scripting in the WordPress MLL Audio Player MP3 Ajax plugin. Attackers can inject malicious scripts that are later executed in the browsers of visitors to the site, enabling defacement, cookie theft, or other client‑side attacks.
Affected Systems
WordPress sites running robertkay MLL Audio Player MP3 Ajax plugin version 0.7 or earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, but the EPSS score of <1 % shows that exploitation is considered rare. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation would involve an attacker providing malicious payloads through a content entry or media upload interface, which the plugin stores and later renders without proper sanitization.
OpenCVE Enrichment
EUVD