Impact
The Vulnerability in the ramanparashar Useinfluence plugin allows an attacker to embed malicious scripts that are stored and later served to any visitor. Once the script is delivered, the attacker could hijack sessions, steal cookies, deface the site, or perform phishing attacks. This Stored XSS flaw can have a high impact on confidentiality and integrity of site users and administrators.
Affected Systems
Any WordPress site that has the Useinfluence plugin installed, including all releases up to and including 1.0.8.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high risk level, but the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker would need to inject a malicious payload through the plugin’s interface, indicating the attack vector involves authenticated users with access to the plugin’s input fields. Once injected, the payload is served to all site visitors without additional input validation.
OpenCVE Enrichment
EUVD