Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of input during page generation. The attacker can inject malicious scripts that execute in the browsers of users who view the affected content, potentially leading to session hijacking, defacement, and unauthorized data exfiltration. The weakness originates from improper input validation and categorizes as CWE‑79.
Affected Systems
WordPress plugin Blog Summary created by scottwallick, versions 0.1.2 beta and earlier, are affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 6.5 denotes a moderate severity, and the EPSS score of <1% indicates a low exploitation likelihood at present. The plugin is not listed in CISA’s KEV catalog. An attacker who can submit or modify content via the plugin can embed scripts that persist in the site; once a user visits the affected page, the injected code runs. The attack vector is remote through the web interface.
OpenCVE Enrichment
EUVD