Impact
The vulnerability is an improper neutralization of input during web page generation, allowing stored cross‑site scripting. An attacker can inject malicious scripts that are later rendered in the site for all visitors, potentially compromising user sessions, executing arbitrary JavaScript, or defacing content.
Affected Systems
The flaw affects the WordPress plugin Magic the Gathering Card Tooltips by grimdonkey, versions up to and including 3.4.0. Any WordPress site that has installed a vulnerable version is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a very low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to send malicious content that the plugin stores and later serves to users; the impact is limited to scenarios where the plugin processes user‑supplied content.
OpenCVE Enrichment
EUVD