Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation, commonly known as Stored Cross-Site Scripting. Attackers can inject malicious scripts that are saved into the WordPress database and later rendered to users. This allows an attacker to execute arbitrary JavaScript in the context of victims who view affected content, potentially facilitating defacement, phishing, or cookie theft, but does not grant attacker code execution on the server itself.
Affected Systems
The issue affects the Toocheke Companion plugin for WordPress, with all releases up to and including version 1.166 being vulnerable. Users of this plugin, regardless of WordPress version, need to verify that they are not running a vulnerable instance.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is below 1%, suggesting a low current likelihood of exploit. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the ability to submit or modify content via the plugin's input mechanisms, which may be limited to users with sufficient privileges or those who can render the vulnerable content. Once injected, malicious scripts will run in the browsers of anyone who loads the affected page.
OpenCVE Enrichment
EUVD