Impact
Improper neutralization of input during web page generation in the peregrinethemes Hester plugin allows attackers to store malicious scripts that execute when the page is viewed by other users. This Stored XSS can lead to session hijacking, defacement, or the delivery of malware.
Affected Systems
The vulnerability impacts the WordPress Hester plugin from peregrinethemes. Any installation of version 1.1.10 or earlier is affected, as the issue is present from an unspecified start up to that release.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of <1% suggests that exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. However, the lack of an official fix does not eliminate risk. The attack requires that an attacker injects a payload into plugin data that is then rendered on the site, likely through an administrator or editor’s ability to create or modify content. Once stored, the code will run in any user’s browser that loads the affected page, enabling the attacker to steal credentials or execute arbitrary actions.
OpenCVE Enrichment
EUVD