Impact
The WP Database Optimizer plugin contains an improper neutralization of user input that leads to stored XSS. The flaw allows attackers to inject malicious scripts that are stored in the database and later served within web pages to other users. This can enable credential theft, session hijacking or defacement, thereby compromising confidentiality and integrity of the affected website.
Affected Systems
Installations of the WordPress plugin WP Database Optimizer developed by Matt Price, version 1.2.1.3 or any earlier release. The vulnerability is present in all instances of the plugin up to and including this version.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of <1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would need to access the plugin’s input interface, typically as a user with administrative or privileged access, to store malicious payloads. Once stored, the scripts execute in the browsers of visitors to the site, creating a client‑side attack vector that can be leveraged even if the attacker lacks server‑side code execution.
OpenCVE Enrichment
EUVD