Impact
An improper neutralization of input during web page generation enables a stored cross‑site scripting flaw that allows an attacker to embed malicious JavaScript into pages rendered by the WordPress GDPR Personal Data Reports plugin. This flaw can be used to steal session cookies, hijack user accounts, deface content, or redirect users to phishing sites, as the injected script executes in the victim’s browser. The vulnerability is classified as CWE‑79 – Improper Neutralization of Input.
Affected Systems
The affected plugin is the WordPress GDPR Personal Data Reports plugin developed by willowsconsulting. All versions from the original release up to and including 1.0.5 are vulnerable; version 1.0.5 is the latest known release that contains the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests a very low current exploitation probability, and the issue is not listed in CISA KEV. Exploitation requires the attacker to submit input that is stored and later rendered to users, typically through the plugin’s data entry interfaces. Once stored, the malicious payload will be delivered to any user who views the affected content, allowing the attacker to execute arbitrary client‑side code.
OpenCVE Enrichment
EUVD