Impact
This vulnerability is a stored cross‑site scripting flaw in the WP Weixin plugin. The plugin fails to properly neutralize user input when generating web pages, allowing a malicious actor to inject and store script code that will later execute in the browsers of any visitor who views the compromised content.
Affected Systems
The flaw affects all installations of the WP Weixin plugin from earlier versions through 1.3.16. Users of the Alexandre Froger WP Weixin plugin who have not upgraded beyond version 1.3.16 are vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of less than 1 % suggests the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Based on the stored‑XSS nature of the flaw, an attacker would need to inject malicious input that is subsequently rendered in a page viewed by other users; however, the exact prerequisites such as authentication level are not detailed in the description.
OpenCVE Enrichment
EUVD