Impact
wp‑maverick’s WP Parallax Content Slider plugin stores user supplied content without properly neutralizing script tags, which can lead to stored XSS. When site visitors view the affected content, malicious script code embedded in the plugin’s fields is executed in their browsers.
Affected Systems
WP Parallax Content Slider plugin by wp‑maverick, versions up to and including 0.9.8. Any WordPress site that uses one of these versions is vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1 % suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker who has the ability to add or edit content through the plugin’s interface; the attacker can persist malicious scripts which are then rendered automatically for all visitors to the site.
OpenCVE Enrichment
EUVD