Impact
The vulnerability is a stored cross‑site scripting flaw that allows malicious scripts to be embedded in data submitted through the Awesome Surveys plugin. When the data is later displayed on a web page, the unsanitized input is rendered, giving an attacker the ability to execute arbitrary JavaScript in the browsers of visitors. This can lead to cookie theft, session hijacking, or defacement of the site.
Affected Systems
All installations of the Will Brubaker Awesome Surveys WordPress plugin version 2.0.10 and earlier are vulnerable; the flaw is present on any site that has not upgraded beyond 2.0.10.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate risk. The EPSS score of less than 1 % suggests that exploitation is currently low. The vulnerability is not listed in CISA KEV. The most likely attack path requires an attacker to submit a malicious survey response through the public or authenticated interface, after which the malicious script is rendered for every visitor who views the survey data.
OpenCVE Enrichment
EUVD