Impact
The WP Smart Tooltip plugin stores user supplied input and later renders it in tooltips without proper sanitization. This flaw permits an attacker to inject arbitrary JavaScript that will execute in the browser of any visitor who loads a page with the tooltip. The injected code can steal session cookies, deface content, or perform further attacks. The weakness is classified as CWE‑79.
Affected Systems
Affected hosts run the WP Smart Tooltip plugin on WordPress sites the plugin version is any of the releases up to 1.0.0. The vulnerability applies to all installations where the plugin’s database fields have not been sanitized, which includes every instance of the plugin before version 1.0.1. The vendor is Nurul Amin.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score is under 1 % meaning a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires access to a page that displays a tooltip populated from the plugin’s data, and an attacker who can supply input to that data. The attack vector is web‐based, being limited to the tooltips rendered by the plugin. No privileged access is required, so a broad attacker base could potentially leverage it if they can serve content that triggers the stored data.
OpenCVE Enrichment
EUVD