Impact
Improper input neutralization in the (Simply) Guest Author Name WordPress plugin allows a DOM‑based XSS flaw. An attacker can inject arbitrary JavaScript that will execute in the browser of any user who views a page containing the vulnerable author name field. This can lead to session hijacking, data theft, or site defacement when the script runs under the victim’s credentials. The weakness is a classic stored input validation error consistent with CWE‑79.
Affected Systems
The vulnerability exists in the (Simply) Guest Author Name plugin by A. Jones for WordPress versions up to and including 4.36. No further version granularity is provided; all releases from the earliest available up to 4.36 are affected.
Risk and Exploitability
The CVSS score of 6.5 classifies this as a moderate severity issue. The EPSS score of less than 1% indicates a very low probability of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to craft a page or request that causes the vulnerable field to render in a victim’s browser—most typically through a link or embedded content—making the threat primarily accidental or socially engineered. Given the DOM‑based nature, the flaw does not affect server‑side components directly.
OpenCVE Enrichment
EUVD