Impact
Stored cross‑site scripting exists in OTWthemes Post Custom Templates Lite due to insufficient neutralization of user input. Attackers can inject malicious scripts into post content, forcing browsers to execute code when a victim views the page. This can lead to session hijacking, data theft or defacement.
Affected Systems
WordPress installations that use the Post Custom Templates Lite plugin version 1.14 or earlier are vulnerable. The plugin is available on the WordPress repository under the OTWthemes brand.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate impact, and an EPSS score of less than 1% suggests that exploitation is currently unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. The attack path requires only that an attacker inject content that is rendered by the plugin, which can be achieved by any user with permission to submit or edit posts. Upon viewing, the malicious code runs in the victim’s browser, regardless of authentication level, and can affect all site visitors.
OpenCVE Enrichment
EUVD