Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of user input during web page generation in the Post‑to‑Post Links plugin. A malicious actor could inject JavaScript that will be rendered in the browsers of users viewing affected posts, leading to session hijacking, defacement, or other user‑level attacks. The weakness is reflected by CWE‑79. The impact is limited to the integrity and confidentiality of data for victims when they visit compromised content, but does not grant broader system access.
Affected Systems
The issue affects the Scott Reilly Post‑to‑Post Links WordPress plugin, specifically the version Easy‑Post‑to‑Post‑Links up to and including 4.2. Sites running any of these versions are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity. The EPSS score of <1% suggests low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Likely the attack requires an authenticated user with permission to add or edit links via the plugin interface, implying that administrative privileges are needed to exploit the flaw. If successful, the script would run in the context of any visitor to the affected post.
OpenCVE Enrichment
EUVD