Impact
The Chess Tempo Viewer plugin for WordPress contains a stored cross‑site scripting vulnerability. User data entered through the plugin is saved without proper neutralization before rendering, allowing an attacker to inject malicious HTML or JavaScript that will execute when a user views the affected page. This can lead to cookie theft, session hijacking, defacement, or redirection to malicious sites.
Affected Systems
WordPress sites that run mliebelt Chess Tempo Viewer plugin version 0.9.5 or earlier are affected. The problem exists from the earliest available version through 0.9.5.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is less than 1%, suggesting a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. To exploit the flaw an attacker would typically need to submit malicious content via the plugin’s input fields, which is stored in the database and rendered to users. Successful exploitation requires the ability to create or modify content through the plugin, so site administrators or users with content‑creation privileges could be at risk.
OpenCVE Enrichment
EUVD