Impact
The vulnerability is an improper neutralization of input during web page generation, allowing an attacker to inject arbitrary scripts that will be executed in the browser of any user who views a page generated by the plugin. This stored cross‑site scripting flaw enables execution of malicious code in the context of the user’s browser.
Affected Systems
The affected product is the Xagio SEO WordPress plugin. Versions from the initial release up to and including 7.0.0.20 are vulnerable. The vulnerability description lists all releases until that version but does not specify earlier minimum versions.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, while the EPSS score of less than 1% suggests exploit attempts are unlikely in the immediate future. The vulnerability is not currently in the CISA KEV catalog. Because the flaw is stored and relies on the plugin handling of user‑supplied content, the attack vector is likely a stored XSS via user inputs that are later rendered by the plugin.
OpenCVE Enrichment
EUVD