Impact
This vulnerability arises from improper neutralization of input during web page generation, allowing attackers to persistently inject malicious scripts into pages served by the EZPlayer plugin. The attacker can store crafted input that will be rendered without proper encoding, potentially stealing user credentials, defacing content, or executing arbitrary commands in the context of site visitors. The weakness is a classic Stored XSS issue identified as CWE‑79.
Affected Systems
The flaw affects the EZPlayer plugin provided by ezmarketing. Any WordPress installation running EZPlayer versions from the earliest available release through and including 1.0.10 is impacted. Versions newer than 1.0.10 are not listed as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying that no confirmed exploits are known at this time. The likely attack vector is through the plugin’s input handling, where an attacker can submit data that the plugin stores and later renders, enabling persistent scripting on the site.
OpenCVE Enrichment
EUVD