Impact
The CVE describes an improper neutralization of input during web page generation in the WeblineIndia Welcome Popup plugin. Stored XSS occurs when user‑controlled data is stored in the database and later rendered without escaping, allowing an attacker to inject malicious JavaScript that executes in the browsers of any visitor.
Affected Systems
All versions of the WeblineIndia Welcome Popup plugin up to and including 1.0.10 are affected. The issue is present from the earliest supported release through 1.0.10, with no mitigations in earlier releases.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% implies a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would typically require an attacker to have the ability to create or modify content that the plugin stores, or to exploit a user’s session after a malicious script has been injected. The attack vector is likely through content‑authoring privileges, but exact requirements are not detailed in the description.
OpenCVE Enrichment
EUVD