Impact
The vulnerability is an improper neutralization of input during web page generation that allows stored cross‑site scripting. Malicious scripts can be entered via the plugin interface and will be rendered when any visitor loads the affected page. This leads to client‑side code execution within the user’s browser.
Affected Systems
The flaw exists in horiyuki Image Switcher for WordPress, affecting all releases from the earliest available through 0.1.1. Any WordPress site that has installed or is still running a version of this plugin that is not newer than 0.1.1 is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of <1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is content or data submission through the plugin’s interface, which can be performed by users with editing or administrative permissions. Once the malicious script is stored, it will execute in the browsers of all visitors who view the affected page, exposing the site to client‑side attacks.
OpenCVE Enrichment
EUVD