Impact
The Lottie Player plugin for WordPress allows authenticated users with Author-level or higher privileges to upload files. These files are not sanitized or escaped, enabling an attacker to embed malicious JavaScript that runs in the browsers of anyone who views the file. The vulnerability stems from insufficient input validation while processing file uploads, resulting in a stored XSS flaw.
Affected Systems
All installations of the Lottie Player – Add Interactive Lottie Animations with Block Support plugin up to and including version 1.1.8 are affected. Site owners who have not upgraded past this version are at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium‑to‑high risk, while the EPSS score of < 1% suggests a low likelihood of real‑world exploitation at present. The flaw is not listed in the CISA KEV catalog. Exploitation requires legitimate credentials with Author or greater access and the ability to upload a malicious animation file; once stored, any site visitor who accesses the file triggers the injected script.
OpenCVE Enrichment
EUVD