Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of input during page generation. An attacker can embed malicious JavaScript into the plugin’s stored data, which is then rendered on the site and executed in the browsers of all visitors. The impact allows attackers to steal session cookies, execute arbitrary client‑side code, and potentially deface or redirect users.
Affected Systems
The affected product is the WordPress Greek Namedays Widget plugin from carrotbits (Eortologio.Net). All installations of this plugin up to and including the 2019‑11‑13 release are vulnerable. Any deployment that continues to use a version equal to or older than the specified date should be considered at risk.
Risk and Exploitability
The CVSS score of 6.5 places this fall under medium severity, while the EPSS score of <1% indicates a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web‑based interface where the plugin stores untrusted input, requiring the target site to be accessible and the plugin installed. Successful exploitation would grant a remote attacker the ability to run arbitrary scripts in the context of any site visitor.
OpenCVE Enrichment
EUVD