Impact
The WP About Author plugin from Jon Bishop is vulnerable to a DOM‑based cross‑site scripting flaw caused by improper neutralization of user input. An attacker can embed malicious JavaScript into the page that the plugin generates, potentially allowing session hijacking, defacement, or other attacks that compromise the confidentiality, integrity, or availability of the affected WordPress site. Because the flaw is client‑side, it can be triggered by any visitor to a page that includes the vulnerable output.
Affected Systems
All installations of the WP About Author plugin with a version of 1.5 or earlier are affected. No specific revisions were indicated beyond the original release; the vulnerability is present from the original release through version 1.5 inclusive.
Risk and Exploitability
The CVSS v3.1 base score is 6.5, which represents a medium‑severity vulnerability. The EPSS score of less than 1% indicates a very low probability of exploitation at present. The issue has not been listed in the CISA KEV catalog. Attackers can trigger the XSS by manipulating URL parameters or plugin settings that are reflected in the rendered page, and the bug does not require authentication, so it can be abused by unauthenticated visitors.
OpenCVE Enrichment
EUVD