Impact
The vulnerability allows an attacker to embed malicious script that is saved by the system and executed whenever a page containing the injected content is viewed. This stored XSS can lead to session hijacking, credential theft, or defacement when victims view the affected pages. The weakness is a classic input validation flaw identified as CWE‑79.
Affected Systems
Maeve Lander’s Rezdy Reloaded WordPress plugin, versions up to and including 1.0.1 are affected. Any WordPress site running the plugin in those releases is susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% suggests exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation would require the attacker to inject malicious content through a writable interface of the plugin, which typically means the attacker must have at least author or administrator privileges. Once injected, the script is delivered to any visitor of the affected page, potentially leaking sensitive information or executing further malware.
OpenCVE Enrichment
EUVD