Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of user input during page rendering in the Social Ninja plugin. An attacker can insert data through the plugin’s interfaces, causing malicious scripts to execute in the browsers of other site visitors. This weakness follows CWE‑79, a typical XSS vulnerability.
Affected Systems
All WordPress installations that use the Social Ninja plugin version 0.2 or earlier are vulnerable. This includes any site that has not upgraded the plugin to a version newer than 0.2, regardless of other configuration.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium‑risk impact. The EPSS score is below 1 %, implying a low probability of exploitation in the current landscape, and the vulnerability is not listed in the CISA KEV catalog. It is inferred that the likely attack vector is through the plugin’s data entry points accessed via a client’s browser. Once payloads are stored, they will affect any visitor who loads the compromised content. The CVE description specifies stored XSS, which allows malicious scripts to run in the browsers of site visitors; specific downstream effects are not detailed in the CVE.
OpenCVE Enrichment
EUVD