Impact
The vulnerability arises from a missing authorization check in the Fare Calculator plugin for WordPress. A malicious actor can submit crafted input that the plugin stores and later renders without proper sanitization, resulting in a stored cross‑site scripting (XSS) vulnerability. Exploitation can lead to defacement, cookie theft, or session hijacking for any user who views the output of the plugin.
Affected Systems
Affected systems are installations of Gopi krishnan Fare Calculator version 1.1 or earlier. The plugin is a WordPress component and may be present on any site that relies on it to compute fare calculations.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity, while an EPSS of less than 1% suggests a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires access to the plugin’s input interface; authentication requirements are not explicitly stated, and an attacker can inject malicious scripts which are subsequently executed in the browsers of all site visitors who view the affected plugin output.
OpenCVE Enrichment
EUVD