Impact
The flaw is an improper neutralization of input during web page generation in the Magic Embeds plugin, enabling a stored cross‑site scripting attack. A malicious actor can inject arbitrary JavaScript that will execute whenever a page containing the embedded content is loaded, potentially compromising user accounts, exfiltrating data, or redirecting users. The weakness corresponds to CWE‑79, a classic XSS vulnerability.
Affected Systems
Miguel Sirvent Magic Embeds plugin, versions 3.1.2 and earlier are affected.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity, while the EPSS score is below 1 %, suggesting a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker adding malicious embed code through the plugin’s input fields, which is then stored and rendered unsanitized on public pages.
OpenCVE Enrichment
EUVD