Impact
This vulnerability is a stored cross‑site scripting flaw in the WordPress plugin Caching Compatible Cookie Opt‑In and JavaScript. The flaw permits an attacker to store malicious scripts that are later executed in the browsers of any user who views pages generated by the plugin. The impact is that attackers can hijack sessions, steal credentials, or otherwise perform malicious actions within the context of the target users. The weakness is CWE‑79.
Affected Systems
The affected software is the WordPress plugin Caching Compatible Cookie Opt‑In and JavaScript developed by matthias.wagner. Any installation of the plugin with a version number of 0.0.10 or lower is vulnerable; newer releases are not impacted.
Risk and Exploitability
The CVSS score of 6.5 classifies the issue as medium severity. The EPSS score of less than 1 % indicates a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack path requires an administrator or a user with permission to modify the plugin’s options to inject the malicious payload, which is then stored and served to all site visitors. While there are no current exploit campaigns noted, the stored‑XSS nature means that a successful exploitation could affect every user who visits a page that renders the affected data.
OpenCVE Enrichment
EUVD