Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation that allows an attacker to store a malicious script in the Optimate Ads plugin and have it rendered on the site.
Affected Systems
The issue affects the Optimate Ads WordPress plugin from its earliest releases up to and including version 1.0.3, which is distributed by shujahat21.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability is considered a moderate‑severity flaw. The EPSS score of less than 1% indicates a low but non‑zero chance of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not a known high‑profile exploit. Based on the description, the likely attack vector involves submitting malicious payloads through plugin input fields that are not properly sanitized, resulting in them being rendered as part of the website’s content.
OpenCVE Enrichment
EUVD