Impact
Improper neutralization of input during web page generation in the CM Header and Footer plugin creates a stored XSS flaw (CWE-79). The vulnerability allows an attacker to embed malicious script into the plugin’s output, which will execute in the browsers of any visitor who loads the affected page, potentially leading to cookie theft, session hijacking, defacement, or further malware delivery.
Affected Systems
The CM Header and Footer plugin from CreativeMindsSolutions, a WordPress add‑on, is vulnerable for all releases up through version 1.2.4. No other vendors or products are listed as affected in the current data.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based stored XSS that requires the attacker to input malicious payloads through the plugin’s administration interface or content entry points, which are not properly sanitized; this inference is made because the official description specifies a stored XSS but does not detail prerequisites. If an attacker can supply input to the plugin, the stored payload will run for all site visitors.
OpenCVE Enrichment
EUVD