Impact
The vulnerability in WP Custom Google Search version 1.0 allows an attacker to forge a request that stores malicious JavaScript into the site’s content, resulting in stored Cross‑Site Scripting (XSS). When an affected user subsequently views the page, the injected script executes in their browser, potentially enabling session hijacking, defacement, or other client‑side attacks. The weakness is a classic CSRF to XSS exploit and is documented as CWE‑352.
Affected Systems
Any WordPress site running the ivanra10 WP Custom Google Search plugin at version 1.0 or earlier suffers from this flaw. No patched version is listed, so any installation of the plugin with a version number of 1.0 or lower remains vulnerable until the plugin is removed or replaced with a correct release.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity, yet the EPSS score of less than 1% indicates a low likelihood of current exploitation. The vulnerability is not in the CISA KEV catalog. Attackers can exploit the flaw by tricking an authenticated administrator into submitting a forged request that writes the malicious script into the plugin’s stored settings. Once deployed, the XSS can affect all site visitors who load the compromised content.
OpenCVE Enrichment
EUVD