Impact
The flaw is a stored Cross‑Site Scripting (XSS) vulnerability, classified as CWE‑79. It allows an attacker to embed malicious JavaScript into content that the Exit Popup Free plugin stores, and that JavaScript runs in the browsers of anyone who accesses the affected content. The description does not specify additional consequences beyond code execution in browsers.
Affected Systems
This vulnerability affects the WordPress plugin Exit Popup Free from promoz73, for all releases up to and including version 1.0. Any WordPress site that has installed any of those versions is susceptible.
Risk and Exploitability
With a CVSS score of 5.9, the vulnerability is rated as moderate severity. The EPSS score of less than 1 % indicates a low current exploitation probability, and the issue is not listed in CISA’s KEV catalog. The likely attack vector, based on the description, would be through the plugin’s input fields that accept and store user‑supplied content, such as popup messages or custom scripts. An attacker would need the ability to submit or modify stored data to inject the XSS payload.
OpenCVE Enrichment
EUVD