Impact
Improper neutralization of user‑controlled input during web page generation in the Annie plugin allows stored cross‑site scripting payloads to be persisted in the database and executed in the browsers of any user who views the affected content. This flaw enables attackers to inject scripts that will run later, potentially leading to unauthorized script execution on the site.
Affected Systems
The flaw exists in the Annie plugin, version 2.1.1 and earlier. Administrators or users with access to the plugin’s content editing interface on WordPress installations using these versions are affected.
Risk and Exploitability
The CVSS score of 6.5 assigns a moderate severity, reflecting the need for the attacker to have the ability to inject content that will be stored and later displayed. The EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves inserting malicious script through the plugin’s data entry fields, requiring sufficient privileges to edit or create content that is rendered for other users. Once inserted, the payload is executed automatically whenever affected content is viewed.
OpenCVE Enrichment
EUVD