Impact
The WP Import Export Lite plugin permits authenticated attackers with Contributor level access or higher to inject arbitrary scripts into stored content via the wpiePreviewData function due to insufficient input sanitization and output escaping. When a user accesses an affected page, the injected script is executed in that user’s browser.
Affected Systems
The flaw affects the Vjinfotech WP Import Export Lite WordPress plugin, all versions up to and including 3.9.27. Users running any of these versions should be considered vulnerable until the plugin is updated.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation currently. The vulnerability has not been listed in the CISA KEV catalog. An authenticated user with Contributor level access or higher can exploit the flaw by injecting scripts through the plugin’s preview or export features, and the attack succeeds when a visitor loads the affected page.
OpenCVE Enrichment
EUVD