Impact
The vulnerable plugin allows malicious JavaScript code to be stored in widget content and then executed in the browsers of any user who views the widget. This stored cross‑site scripting flaw can expose user data or enable further malicious actions when the content is displayed.
Affected Systems
WordPress sites that have the MeinTurnierplan.de Widget Viewer plugin by meinturnierplan in any version up to and including 1.1.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker can inject scripts through the plugin's input fields in the WordPress administration interface; when stored, the scripts are rendered unsanitized in any visitor’s browser.
OpenCVE Enrichment
EUVD