Impact
The Easy Tweet Embed plugin for WordPress contains a DOM‑based cross‑site scripting (XSS) flaw that allows an attacker to inject arbitrary client‑side scripts into pages rendered by the plugin. Successful exploitation can lead to theft of user credentials, defacement of content, or execution of further malicious actions within the victim’s browser context. The vulnerability originates from improper neutralization of user‑supplied input during page generation, as classified by CWE‑79.
Affected Systems
The flaw is present in all versions of Tom Ewer’s Easy Tweet Embed plugin up to and including version 1.7. Users running any of those releases are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, while the EPSS score of less than 1 % signals that active exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, and it is a DOM‑based XSS that could be triggered when a user visits a page containing a maliciously crafted tweet embed URL or input. Based on the description, it is inferred that this is the likely attack vector, even though the official advisory does not explicitly state it. The attack requires no privileged access and can be performed from any network region where the site is reachable.
OpenCVE Enrichment
EUVD