Impact
Improper neutralization of input during page generation in the Clearout Email Validator plugin for WordPress enables a stored cross‑site scripting flaw. In a stored XSS, malicious code can be entered via the plugin, saved to the database, and later rendered to every visitor who loads the affected page. The flaw has the potential to execute arbitrary JavaScript within the browser context of site users. Based on the description, it is inferred that the injection occurs via input fields in the plugin, as the attack vector is not explicitly stated in the payload.
Affected Systems
This vulnerability affects the Clearout Email Validator plugin by clearoutio on WordPress installations. Versions through and including 3.2.0 are impacted; any site running those versions is at risk.
Risk and Exploitability
The CVSS base score of 5.9 categorizes the flaw as moderate. Its EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers could attempt to inject script via the plugin’s input fields, and the stored nature of the flaw means the compromise persists across page loads, potentially affecting all users who view the content.
OpenCVE Enrichment
EUVD