Impact
Improper neutralization of user input in the Authorsy plugin allows an attacker to inject malicious scripts that will be stored in the database and served to all visitors of a site. When a victim’s browser renders the impacted page, the injected code executes with the same privileges as the page, potentially leading to cookie theft, session hijacking, defacement, or the launching of further attacks against the visitor.
Affected Systems
The vulnerability is present in all releases of Authorsy version 1.0.5 and earlier built by themeplugs. Any WordPress site that has the plugin installed at a version equal to or lower than 1.0.5 is vulnerable; newer releases are not listed as affected.
Risk and Exploitability
With a CVSS base score of 6.5, the flaw is of moderate severity. The EPSS score indicates a very low likelihood of exploitation at present, and the vulnerability is not part of the CISA KEV catalog. The attack likely requires access to a component that accepts unescaped user input in the plugin, such as a comment or author description field, and the attacker would then craft input containing JavaScript that the site stores and later delivers to other users.
OpenCVE Enrichment
EUVD