Impact
The Unlimited plugin for WordPress contains a stored cross‑site scripting flaw that fails to neutralize user‑supplied input when rendering web pages. An attacker can inject malicious script that will run in the browsers of any user who views the affected page, potentially allowing session hijacking, credential theft, or defacement of the site. The weakness is classified as CWE‑79, indicating an input‑validation and output‑encoding issue.
Affected Systems
The vulnerability applies to the Unlimited plugin produced by bensibley, affecting all releases from the earliest available version up through 1.45. Systems running the plugin in any of those versions are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity issue. The EPSS score of less than 1% reflects a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. While the attack vector is not explicitly detailed, it is likely that an authenticated or unauthenticated user can induce the bad input through the plugin’s storage endpoints, enabling the XSS payload to persist and later be delivered to other users.
OpenCVE Enrichment
EUVD