Impact
The vulnerability is a classic cross‑site scripting flaw. The plugin fails to neutralize input before it is rendered on web pages, allowing attackers to store malicious scripts that will execute in the browsers of any user who views affected content. This can lead to session hijacking, defacement, or data exfiltration. The weakness is classified as CWE‑79.
Affected Systems
The flaw affects the WordPress jAlbum Bridge plugin developed by mlaza, impacting all releases up to and including version 2.0.18. WordPress sites running this plugin are susceptible when the plugin's features that store user‑supplied data are enabled.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score of < 1% shows a very low likelihood of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve crafting malicious input through the plugin's administrative interface or forms that are stored and later displayed to visitors; however, exact entry points are not detailed in the available information.
OpenCVE Enrichment
EUVD