Impact
Zeshan Abdullah’s Like dislike plus counter WordPress plugin contains a Cross‑Site Scripting (CWE‑79) flaw that allows an attacker to store and later deliver arbitrary script into web pages rendered by the plugin. Based on the description, it is inferred that the attacker can submit unsanitized data – for example through the like/dislike interface or any publicly accessible form – and then inject malicious JavaScript that executes in the context of site visitors. Stored XSS can lead to session hijacking, credential theft, or defacement, representing a moderate but non‑zero risk to confidentiality, integrity, and availability of the site’s users.
Affected Systems
The vulnerability exists in the WordPress plugin known as Like dislike plus counter, authored by Zeshan Abdullah, across all released versions up through and including 1.0. Sites running any of those versions are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score of less than 1 % suggests that exploitation is currently uncommon, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by submitting payloads through any front‑end interface that stores user input. Because the flaw is stored, no further action is required from the victim once the malicious code is executed.
OpenCVE Enrichment
EUVD