Impact
The Prezi Embedder plugin for WordPress has a stored cross‑site scripting vulnerability (CWE‑79). The flaw arises from failure to properly neutralize user input when generating web pages, allowing malicious code to be stored in the database. When the affected content is viewed, the injected scripts execute in the browsers of any user accessing the page, potentially exposing the plugin to unintended script execution.
Affected Systems
This vulnerability affects the Dan Rossiter Prezi Embedder WordPress plugin for any version up to and including 2.1. The plugin must be installed in a WordPress site, and an attacker must have the ability to submit or edit content that is processed by the plugin.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the plugin’s content‑submission interface, requiring an authenticated user with permission to add or edit embedded Prezi widgets; once malicious input is stored, it will execute whenever the affected page is rendered.
OpenCVE Enrichment
EUVD