Impact
An attacker can inject malicious scripts into stored comments processed by the Stop Comment Spam plugin, causing browsers of all site visitors to execute the payload. The injected code can steal authentication cookies, hijack user sessions, deface the site, or redirect users to phishing domains. This vulnerability is a classic Stored XSS flaw classified under CWE‑79, compromising confidentiality, integrity, and availability of the web platform.
Affected Systems
WordPress sites that use the pedjas Stop Comment Spam plugin in any version up to and including 0.5.3 are affected. The vulnerability is present in the default configuration of the plugin across all WordPress installations that have not upgraded beyond version 0.5.3.
Risk and Exploitability
The CVSS score of 7.1 reflects high severity, while the EPSS < 1% suggests that, as of this analysis, the probability of real‑world exploitation is low. The issue is not listed in CISA's KEV catalog. An attacker can typically exploit the flaw by submitting a crafted comment or content item through the normal comment workflow, after which the malicious script is rendered for all users who view the affected content. The impact is limited to browsers that render the plugin output, and is mitigated by proper input sanitization or removal of the plugin.
OpenCVE Enrichment
EUVD