Impact
The vulnerability is a stored XSS flaw caused by improper neutralization of script‑related HTML tags. An attacker can embed malicious JavaScript that is persisted in the database and executed whenever a page rendering that content is accessed, potentially enabling credential theft, session hijacking or defacement.
Affected Systems
The MicroPayments plugin for WordPress, provided by videowhisper, is affected. All versions from the earliest releases through and including 2.9.29 are vulnerable.
Risk and Exploitability
With a CVSS score of 6.5 the flaw represents medium severity, and an EPSS score of less than 1% indicates a low likelihood of current exploitation. The flaw is not listed in CISA’s KEV catalog. Exploitation is achieved by submitting malicious payloads via the plugin’s interface; the stored script is then executed in the browsers of any user who views the affected content.
OpenCVE Enrichment
EUVD