Impact
Improper neutralization of script‑related HTML tags in the Slides & Presentations plugin allows an attacker to inject arbitrary JavaScript into a web page. This basic XSS could be used to run malicious scripts in the browsers of any visitor to a page that displays the injected content, potentially stealing credentials or manipulating the page. The vulnerability is classified as CWE‑80, reflecting the lack of proper input validation or output encoding.
Affected Systems
WordPress sites running the Slides & Presentations plugin by Ella Van Durpe created through version 0.0.39 are susceptible. Any site that relies on this plugin for slide or presentation functionality and has not upgraded past 0.0.39 is at risk.
Risk and Exploitability
The CVSS score of 5.4 places the issue in the medium range, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. The likely attack vector is via the web interface where an attacker can submit or edit slide content; the insecure rendering of that content then injects code into the page seen by other users. Because the flaw resides in output handling, an attacker with the ability to create or alter slides can exploit it without requiring additional privileges.
OpenCVE Enrichment
EUVD