Impact
The vulnerability allows an attacker to inject malicious JavaScript that is permanently stored by the plugin. Once injected, the script runs whenever page content is rendered, enabling data theft, session hijacking, defacement, or the spread of malware. The weakness is an improper input neutralization flaw, identified as CWE‑79.
Affected Systems
WordPress sites that have the Strx Magic Floating Sidebar Maker plugin version 1.4.1 or earlier installed are affected. The problem exists in all releases up to and including this version.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score is below 1 %, suggesting a relatively low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is a CSRF‑enabled request from a malicious web page that submits malicious content to the plugin, requiring an attacker to be able to induce a logged‑in administrator to visit the page. Successfully exploited, it permits persistent client‑side compromise of every visitor to the affected site.
OpenCVE Enrichment
EUVD