Impact
The vulnerability is an improper neutralization of input that allows stored cross‑site scripting. When an attacker injects malicious code that is later rendered in a user’s browser, the attacker can run scripts in the context of the site, potentially compromising data or hijacking sessions.
Affected Systems
WordPress sites that have the Rodolphe MOULIN List Mixcloud plugin version 1.4 or earlier. The vulnerability applies to all releases from an unspecified initial version up to and including 1.4.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The flaw is not catalogued in CISA’s KEV list. Attackers can exploit the stored XSS remotely by submitting malicious content to any vulnerable input field, which then executes in the browsers of other users viewing the polluted page.
OpenCVE Enrichment
EUVD