Impact
The Donate visa WordPress plugin contains a missing authorization flaw that permits an attacker to store malicious JavaScript in the plugin’s data, creating a stored XSS condition. When a victim browses content that includes the injected script, the code runs in the victim’s browser, potentially stealing session cookies, defacing pages, or redirecting the user. The weakness corresponds to CWE‑862 (Missing Authorization).
Affected Systems
This vulnerability affects the Donate visa plugin released by Saul Morales Pacheco, version 1.0.0 and all earlier releases that have been deployed on WordPress sites. Any site running one of those versions is susceptible to the stored XSS attack.
Risk and Exploitability
The CVSS score of 6.5 signals a moderate risk, but the EPSS value of <1% indicates that the exploitation probability is currently low and this issue is not listed in the CISA KEV catalog. The likely attack vector is web‑based; an attacker can inject malicious code through any interface that accepts input for the plugin, whether authenticated or unauthenticated. Consequently, the threat is moderate and can be mitigated effectively by addressing the plugin’s version or configuration.
OpenCVE Enrichment
EUVD