Impact
The vulnerability allows attackers to insert arbitrary JavaScript into pages that use the Jenst Mobile Navigation plugin. The plugin stores user input without proper escaping, making the injected script persist as part of the site’s content. When visitors load any affected page, the malicious code executes in their browser, potentially stealing session cookies, defacing the site, or performing unauthorized actions on the victim’s behalf.
Affected Systems
WordPress sites that run the Jenst Mobile Navigation plugin version 1.5 or earlier. All releases from the plugin’s earliest available version through 1.5 are affected.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. The attack vector is web‑based; an attacker can supply the malicious payload via the plugin’s administrative interface or content editor, which is then stored and rendered for all site visitors. Because the flaw is stored XSS, any user who views a page that incorporates the plugin can be exposed to the injected script.
OpenCVE Enrichment
EUVD