Impact
The vulnerability is a stored cross‑site scripting (XSS) flaw in the Melipayamak WordPress plugin. It occurs when the plugin fails to properly neutralize user input before rendering it in web pages, allowing an attacker to inject arbitrary scripts that are subsequently executed by visitors. This can lead to session hijacking, defacement, or the theft of sensitive information accessed by the affected users.
Affected Systems
Melipayamak: Melipayamak plugin version 2.2.12 or lower is affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity. The EPSS score is below 1%, suggesting that the likelihood of exploitation is low at present. It is not listed in the CISA KEV catalog. An attacker would need to inject malicious input through a feature of the plugin that stores user data. Once stored, the code is executed in the browser of anyone who views the affected page, making the attack vector local to the WordPress site’s front‑end but potentially impacting all site visitors.
OpenCVE Enrichment
EUVD