Impact
This vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject arbitrary scripts into the webpage output of the WordPress Better WishList API plugin. The injected code is executed when any site visitor loads a page that displays the malicious content, enabling defacement, cookie theft, or background data exfiltration. The weakness is classified as CWE‑79 (Improper Neutralization of Input).
Affected Systems
The issue affects the Better WishList API plugin (rickonline_nl) in WordPress. All releases from the earliest version through 1.1.3 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity risk. The EPSS score of less than 1% shows a low exploitation probability at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is stored, an attacker would need to supply malicious input that is accepted and rendered by the plugin – likely through an authenticated or publicly available data entry form. Successful exploitation would compromise the client side of any visitor to the site.
OpenCVE Enrichment
EUVD