Impact
Improper neutralization of input during web page generation is present in WP Chrono code, enabling DOM‑based cross‑site scripting that allows an attacker to inject arbitrary JavaScript into a victim’s browser. This flaw can lead to malicious script execution when a user visits a crafted page, potentially compromising session cookies, defacing the site, or hijacking user interactions.
Affected Systems
The vulnerability affects the WP Chrono WordPress plugin from any version up to and including 1.5.4, supplied by milan.latinovic. Users running 1.5.4 or older must update the plugin to a newer release where the issue is fixed.
Risk and Exploitability
With a CVSS score of 6.5 the flaw carries moderate severity. The EPSS score is reported to be below 1 %, indicating a low probability of exploitation at this time. It is not listed in CISA’s KEV catalog, which suggests no known widespread exploitation. Attacks would be delivered through client‑side input or URLs that reach the plugin’s output routines, allowing remote code evaluation in the context of the victim’s session.
OpenCVE Enrichment
EUVD