Impact
The vulnerability is a stored cross‑site scripting flaw in the Restrict Anonymous Access plugin that allows malicious JavaScript to be embedded into pages rendered by WordPress. This can enable attackers to perform session hijacking, data theft, or defacement when site visitors or administrators view affected pages. The flaw is classified as CWE‑79 and the CVSS score of 6.5 indicates a moderate severity.
Affected Systems
The issue affects Christian Leuenberg’s Restrict Anonymous Access WordPress plugin versions 1.2 and earlier. Any WordPress installation with this plugin active is potentially vulnerable.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, suggesting a low likelihood of widespread exploitation. The CVSS score reflects moderate potential impact. Based on the description, the likely attack vector is inferred to be an attacker submitting a malicious value through the plugin’s configuration or content entry interface, which would store the payload in the database and serve it to all users who load the affected page, thereby executing arbitrary JavaScript.
OpenCVE Enrichment
EUVD