Impact
The More Mime Type Filters plugin for WordPress contains a stored cross‑site scripting flaw caused by improper neutralization of user input during web page generation. An attacker who can supply data that will be stored by the plugin can inject malicious scripts that will later be rendered for any user who views the affected page, potentially enabling credential theft, session hijacking or defacement. This flaw falls under CWE‑79.
Affected Systems
The vulnerability affects the Kailey (trepmal) More Mime Type Filters plugin, specifically all releases from unversioned through 0.3 inclusive. Sites that have installed or are running this plugin version are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity while the EPSS score of less than 1 % suggests a low but non‑zero chance of exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack path is that an authenticated or privileged user submits malicious input via the plugin’s interface, which is stored and later rendered without proper escaping; this inference follows from the description that the issue is a stored XSS created through the plugin’s input handling.
OpenCVE Enrichment
EUVD