Impact
The Flatty flatty-flat-admin-theme plugin for WordPress has a stored XSS flaw due to improper neutralization of input during web page generation. A malicious actor can embed malicious script that will be rendered for any user who views affected pages, potentially leading to cookie theft, session hijacking, defacement, or delivery of malware, depending on the privileges of the target user.
Affected Systems
This vulnerability exists in all versions of the Flatty plugin up to and including 2.0.0, released by vendor Michele Marri. Any WordPress installation using Flatty flatty-flat-admin-theme 2.0.0 or older is impacted.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity. The EPSS score of less than 1 % suggests a low probability of exploitation in the field. The vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is that attackers can exploit it by submitting crafted input that is stored by the plugin and subsequently rendered unescaped, typically via an authenticated administrator or contributor capable of adding content to the site. Once payloads are executed, they run in the context of the vulnerable site, enabling attackers to manipulate the session of any visitor.
OpenCVE Enrichment
EUVD