Impact
This vulnerability is an improper neutralization of input during web page generation, resulting in stored cross‑site scripting. An attacker who can inject content through the Easy Page Transition plugin could cause browsers to execute arbitrary JavaScript when victims view the affected page. Based on the type of XSS and typical attack outcomes, it is inferred that session hijack, defacement, or credential theft could result. The impact is limited to the web page context but could compromise user accounts if properly executed.
Affected Systems
The flaw affects the Logan Carlile Easy Page Transition WordPress plugin up to and including version 1.0.1. Any WordPress site that has installed and activated this plugin is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of below 1% suggests a very low likelihood of exploitation, and the vulnerability is not currently listed in CISA’s KEV catalog. The description indicates that an attacker could inject malicious content through the Easy Page Transition plugin. Once injected, any visitor to the affected page could be impacted.
OpenCVE Enrichment
EUVD