Impact
Improper neutralization of user input in WordPress Awesome Timeline plugin versions up to 1.0.1 creates a stored XSS flaw. Malicious scripts can be embedded into timeline content and will execute in the browsers of any visitor viewing pages that display that content, enabling attackers to hijack sessions, deface sites, or exfiltrate data. The weakness corresponds to CWE-79.
Affected Systems
The flaw affects installations of the Nitesh Awesome Timeline plugin on WordPress sites running any released version up to and including 1.0.1. Site administrators using this plugin in its vulnerable state are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating a medium severity. Its EPSS score is less than 1%, suggesting a low probability of exploitation at this time, and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers could exploit it by inserting malicious script payloads into the plugin’s content through any interface that accepts user input, such as timeline entry editors. Successful exploitation would result in client‑side script execution within the context of the site, potentially leading to user‑session hijacking or defacement.
OpenCVE Enrichment
EUVD