Impact
An attacker can inject malicious script into the tooltip text of the Magic the Gathering Card Tooltips plugin. When a user views the tooltip, the stored script is rendered in their browser, enabling execution of client‑side code. This flaw arises from the plugin’s failure to properly escape user‑supplied content.
Affected Systems
WordPress sites running the grimdonkey Magic the Gathering Card Tooltips plugin version 3.5.0 or earlier are vulnerable. Any installation that has not upgraded beyond the 3.5.0 release is at risk.
Risk and Exploitability
The vulnerability scores a CVSS of 7.1, indicating a moderate to high severity. The EPSS score is below 1 %, implying a low current likelihood of exploitation, and it is not listed in the CISA KEV catalog. Exploitation would require an attacker to embed malicious payloads into tooltip content that is then stored and displayed to other users, usually via the plugin’s front‑end input interface.
OpenCVE Enrichment
EUVD