Impact
The Top Flash Embed plugin fails to neutralize user‑supplied content before rendering it in web pages, resulting in a stored cross‑site scripting flaw (CWE‑79). This vulnerability allows malicious JavaScript to be stored through the plugin’s input mechanisms and then executed in the browsers of any visitor to a page that displays that stored content.
Affected Systems
The vulnerability impacts foo123’s Top Flash Embed WordPress plugin, version 0.3.4 and all earlier releases. Sites that have any of these versions installed are susceptible.
Risk and Exploitability
With a CVSS score of 6.5, the flaw poses a moderate severity risk. The EPSS score of <1% indicates a low current probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers would likely exploit the plugin's data input mechanisms, inserting malicious scripts into stored content that is subsequently rendered for site visitors.
OpenCVE Enrichment
EUVD