Impact
The WordPress WP krpano plugin contains a stored cross‑site scripting flaw. Improperly neutralized input during web page generation allows an attacker to inject malicious JavaScript that executes in the context of site visitors. This can facilitate session hijacking, defacement, data exfiltration, or the delivery of further malware, compromising the integrity and confidentiality of the site content.
Affected Systems
The vulnerability affects the No‑Nonsense WP krpano plugin for WordPress, impacting all versions from the earliest release through version 1.2.1 inclusive. Users running any of these releases are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of < 1% reflects a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote user submitting malicious input via the plugin’s configuration or content entry interface; based on the description, it is inferred that the flaw can be exploited by anyone with write access to the plugin’s input fields.
OpenCVE Enrichment
EUVD