Impact
The Blur Text plugin fails to neutralize user input before rendering it on a web page, allowing attackers to inject malicious scripts that execute in the browsers of site visitors. This stored cross‑site scripting flaw enables attackers to run arbitrary JavaScript in the context of the vulnerable site, potentially compromising user sessions, stealing credentials, injecting tracking code, or modifying page content. The weakness is a classic example of a CWE‑79 type flaw.
Affected Systems
The vulnerability affects the Blur Text plugin developed by Linnea Huxford, for all releases from the earliest to version 1.0.0. Any WordPress site that has not upgraded beyond 1.0.0 is vulnerable.
Risk and Exploitability
With a CVSS score of 6.5 the flaw is considered medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation in the wild; the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector involves an attacker having permission to submit or edit content that the plugin processes—such as an administrator, author, or contributor role. Once a malicious payload is stored, every visitor to pages displaying that content will execute the script, creating a significant risk of data theft or defacement.
OpenCVE Enrichment
EUVD