Impact
This vulnerability corresponds to CWE‑79. Improper neutralization of input during web page generation allows a stored cross‑site scripting flaw in the Leaky Paywall plugin. Because the vulnerability accepts unfiltered content that is later rendered in a browser, an attacker who can inject script into the plugin’s stored data can cause arbitrary code to execute when any user views the affected page. This can lead to session hijacking, credential theft, or defacement, representing a moderate but real threat to confidentiality and integrity of site visitors.
Affected Systems
WordPress sites using the Leaky Paywall plugin by ZEEN101, version 4.21.7 or earlier. The attacker can target any instance of this plugin within the WordPress environment.
Risk and Exploitability
The CVSS score of 6.5 classifies the issue as moderate severity, while an EPSS score of less than 1% indicates a low likelihood of exploitation in the current environment. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to craft an input that the plugin accepts and stores—likely via administrative or user‑submitted content—so that it later appears in a rendered page. Because the flaw is stored, any visitor to the affected page could inadvertently run the malicious script.
OpenCVE Enrichment
EUVD