Impact
The Feedburner Optin Form plugin for WordPress contains a stored cross‑site scripting flaw caused by improper sanitization of user‑supplied data. When a malicious payload is injected into the plugin’s stored configuration or form fields, the payload is later rendered without escaping in page content served to site visitors. This allows an attacker to execute arbitrary JavaScript in the browsers of anyone who loads the affected page, potentially leading to credential theft, session hijacking, defacement, or other malicious actions.
Affected Systems
WordPress sites that include jp2112 Feedburner Optin Form plugin version 0.2.8 or earlier. The vulnerability exists in all releases up to and including 0.2.8 and no official patch is available for earlier minor releases.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a low probability of exploitation in the wild. The issue is not listed in CISA KEV. Based on the description, the likely attack vector involves a user—either authenticated or unauthenticated depending on plugin configuration—injecting a script into a stored plugin field, which is then served unescaped to site visitors. Successful exploitation would allow arbitrary JavaScript execution on the victim’s browser.
OpenCVE Enrichment
EUVD