Impact
The flaw arises from inadequate input sanitization in the Orbisius Simple Notice plugin, allowing an attacker to embed malicious JavaScript into a notice that is later rendered on the site. Because the input is stored, the script is persisted and served to all visitors who view that notice. An attacker can then execute code in the visitor’s browser context, potentially stealing session cookies, defacing the page, redirecting traffic or loading additional malicious payloads.
Affected Systems
WordPress sites that have installed the Orbisius Simple Notice plugin in any version from the initial release up to and including 1.1.3 are affected. This includes all sites where the plugin is active, regardless of the WordPress core or theme version.
Risk and Exploitability
The CVSS score of 5.9 reflects moderate severity, while the EPSS score below 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, suggesting no widely documented exploitation. The most likely attack vector is an authenticated administrator who has permission to create or edit notices within the plugin. Once a malicious notice is stored, every visitor to the site receives the script when rendering the notice, creating an opportunity for data theft or defacement.
OpenCVE Enrichment
EUVD