Impact
Giveaways and Contests by PromoSimple 1.24 and earlier contain a stored cross‑site scripting flaw caused by insufficient neutralization of user input when generating web pages. An attacker who can insert content through the plugin’s input fields could cause malicious scripts to run in the browsers of any visitor who views the affected page, potentially allowing session hijacking, defacement, or data theft.
Affected Systems
Any WordPress installation that has the Sam Brodie Giveaways and Contests by PromoSimple plugin version 1.24 or older is vulnerable. The plugin must be present, and its input mechanisms must be reachable by users to exploit the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity; however the EPSS score is below 1%, suggesting low probability of current exploitation, and the issue is not listed in the CISA KEV catalog. The attack vector is likely an untrusted user input that is stored and later rendered without proper escaping. If an attacker can submit content through the plugin, they may trigger the vulnerability by embedding script tags or other executable payloads into stored fields. The impact remains confined to the victim’s browser, but a compromised browser can compromise the user’s session, credentials, and potentially the site’s data if the attacker leaks stolen data to the plugin owner.
OpenCVE Enrichment
EUVD