Impact
The IFrame Widget plugin contains a stored XSS flaw caused by inadequate input sanitization when users store content for display. An attacker who can insert content into the widget configuration could embed malicious scripts that run in the browsers of any site visitor. This could lead to credential theft, defacement, or session hijacking. The flaw is a typical input validation weakness labeled CWE‑79 and results in a medium security risk.
Affected Systems
Debashish’s IFrame Widget plugin for WordPress is affected in all releases up to and including version 4.1. WordPress sites installing or using the plugin at these versions are potentially vulnerable; sites that have already applied newer versions are safe.
Risk and Exploitability
The CVSS score of 5.9 classifies the issue as medium severity, while the EPSS score of less than 1% indicates a low probability of exploitation at the time of assessment. Based on the description, the likely attack vector is the WordPress admin interface where users can input widget content, enabling stored XSS. No additional access requirements are specified, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation.
OpenCVE Enrichment
EUVD