Impact
The vulnerability is an improper neutralization of input during web page generation that allows stored XSS. Malicious scripts can be injected and later executed in visitors’ browsers when the affected content is displayed.
Affected Systems
CrazyCric Ultimate Live Cricket WordPress Lite. Versions up to and including 1.4.2 are vulnerable.
Risk and Exploitability
The CVSS base score is 6.5, indicating a medium impact. The EPSS score is less than 1%, suggesting a low probability of exploitation in the near term. The vulnerability is not listed in CISA KEV. Exploitation requires an attacker to insert code that the plugin stores and have a user view that content; the attack is client‑side and does not entail server‑side code execution.
OpenCVE Enrichment
EUVD