Impact
The Custom Content Scrollbar plugin for WordPress contains a stored cross‑site scripting flaw caused by improper neutralization of user input during page generation; attackers can inject arbitrary JavaScript that executes in the browsers of all visitors to the affected page, potentially enabling session hijacking, defacement, or theft of sensitive data.
Affected Systems
SoftHopper Custom Content Scrollbar versions up to and including 1.3, used within WordPress sites, are impacted by this vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a low likelihood of current exploitation, and the vulnerability is not listed in the CISA KEV catalog; it can be exploited by anyone who loads the plugin’s output, with no authentication required, allowing client‑side compromise after visiting the site.
OpenCVE Enrichment
EUVD