Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of input during the generation of web pages. Untrusted data is stored by the plugin and later displayed without adequate escaping, allowing an attacker to inject malicious JavaScript that runs in the browsers of any site visitor. This could enable session hijacking, credential theft, or defacement of the site. The weakness corresponds to CWE‑79.
Affected Systems
The affected product is Eli's EZ SQL Reports Shortcode Widget and DB Backup WordPress plugin. Versions up to and including 5.21.35 are vulnerable. No specific patch version is stated; therefore any release newer than 5.21.35 should be considered safe.
Risk and Exploitability
The CVSS base score of 6.5 indicates medium severity. An EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to supply malicious input through the plugin’s interface; once stored, the code runs in all browsers that render the affected content.
OpenCVE Enrichment
EUVD