Impact
Improper neutralization of user input during web page generation allows an attacker to store malicious scripts that will execute in a visitor's browser when they view affected content. This client‑side script execution can lead to session hijacking, cookie theft, defacement, or the delivery of phishing content, thereby compromising user confidentiality and integrity.
Affected Systems
WordPress Broadly for WordPress plugin, versions from the initial release through 3.0.2, is affected. The vulnerability exists in the plugin’s data handling and rendering logic for user‑supplied content.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is through the plugin’s input fields that store content permanently and display it later, allowing an attacker to embed malicious script that will run when any user loads the affected page.
OpenCVE Enrichment
EUVD