Impact
The flaw is a stored XSS vulnerability in the Upload Quota per User WordPress plugin. When the plugin accepts user input without properly neutralizing it, malicious code can be saved and later executed in the context of the website’s pages. Because the code is stored, any visitor who loads the affected page will have the script run in their browser.
Affected Systems
All WordPress installations that have a version of the plugin from any release up to and including 1.3 are affected. Versions prior to 1.0 and any installation of the plugin that is older than the latest release are included in the scope.
Risk and Exploitability
The CVSS base score is 5.9, indicating moderate severity. The EPSS score is listed as less than 1 percent, denoting a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to deliver malicious content that is stored and displayed by the plugin. No other prerequisites are noted in the description.
OpenCVE Enrichment
EUVD