Impact
The vulnerability is an improper neutralization of input during web page generation (CWE-79). The Compare Ninja plugin stores malicious script code when input is not adequately sanitized, allowing an attacker to inject scripts that execute in the browsers of visitors who view the affected content. This can lead to session hijacking, data theft, or defacement of the site.
Affected Systems
The vulnerability affects the Common Ninja Compare Ninja plugin for WordPress, with all releases up to and including version 2.1.0 exposed to risk.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity, while the EPSS score of less than 1% suggests low exploitation probability in the short term. The vulnerability is not yet listed in the CISA KEV catalog. Attackers would likely target the plugin’s administration or content‑creation interfaces to submit malicious payloads that are later rendered on the front‑end, making the stored XSS attractive to attackers with knowledge of the site’s plugin usage.
OpenCVE Enrichment
EUVD