Impact
The FastBook plugin contains an improper input neutralization flaw that allows an attacker to store arbitrary JavaScript code within the plugin’s data. When a victim subsequently views the affected page, the injected script runs in their browser, potentially leading to credential theft, session hijacking, or defacement. The vulnerability is classified as CWE‑79 and is a stored cross‑site scripting issue.
Affected Systems
This weakness affects FasterThemes FastBook, any installation running version 1.1 or earlier. No specific sub‑versions are identified beyond the upper bound of 1.1; earlier releases are implicitly covered by 'from n/a through <= 1.1'.
Risk and Exploitability
The CVSS base score of 7.1 highlights a high severity. EPSS is reported as less than 1 %, suggesting that exploitation is not yet widespread, and the entry is not listed in the CISA KEV catalog, indicating no confirmed public exploitation. The attack vector is inferred to be a web‑based compromise: an attacker can submit a malicious payload via the plugin’s input fields, which is then stored and later rendered to users. While no advanced privileges are required, the impact can be severe for any user who interacts with the compromised content.
OpenCVE Enrichment
EUVD