Impact
The vulnerability is an improper neutralization of input during web page generation in the Demo User DZS plugin up to version 1.1.0, resulting in stored XSS that can be triggered whenever an authenticated user views the affected data. An attacker can inject arbitrary JavaScript to execute in the victim’s browser, allowing theft of session cookies, defacement of the site, or other malicious actions that compromise confidentiality and integrity of the site administration interface.
Affected Systems
The affected product is the Demo User DZS WordPress plugin from the vendor digitalzoomstudio. All releases through version 1.1.0 are impacted; no newer versions are listed as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high impact, but the EPSS score of < 1 % shows a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be web‑based: an attacker must first inject malicious payload into the plugin’s input fields (such as form data or stored content) and then ensure an authenticated user views that stored data to trigger the script. The stored nature of the flaw means that the vulnerability persists until the data is cleaned or the plugin is updated.
OpenCVE Enrichment
EUVD