Impact
The vulnerability is a stored cross‑site scripting flaw that allows an attacker to embed malicious JavaScript into the Leyka plugin’s data stores, which is then rendered on the website. This defect originates from improper neutralization of input during web page generation. The weakness is identified as CWE‑79.
Affected Systems
The affected product is the VaultDweller Leyka WordPress plugin, all releases up to and including 3.31.8. Users running any of these versions are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1 % suggests a low likelihood of exploitation. The vulnerability is not listed in CISA KEV. The stored XSS flaw permits an attacker to inject arbitrary JavaScript that will be rendered when the plugin’s content is displayed to users.
OpenCVE Enrichment
EUVD