Impact
Anshi Solutions Category D3 Tree implements a stored cross‑site scripting flaw that fails to neutralize user input when generating web pages. Injected script code is saved and executed in the browsers of anyone who views the affected page, potentially allowing cookie theft, session hijacking, defacement or the delivery of arbitrary JavaScript to unsuspecting users.
Affected Systems
WordPress sites that use the Category D3 Tree plugin from any release up through version 1.1 are vulnerable. The issue affects all plugin versions whose release number falls in the range "n/a through <= 1.1."
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity vulnerability, and the EPSS score of less than 1% shows a very low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a web based injection where an authenticated user with permission to add or edit categories can submit malicious script. Once stored, the script runs in the victim’s browser whenever the page is rendered.
OpenCVE Enrichment
EUVD