Impact
Improper neutralization of user input in the Breaking News WP plugin allows attackers to embed arbitrary JavaScript that is stored and rendered in web pages. When a visitor loads a page that displays the attacker‑controlled content, the malicious script executes in the victim’s browser, potentially enabling session hijacking, cookie theft, defacement, or redirecting the user to malicious sites.
Affected Systems
The vulnerability impacts installations of the doit Breaking News WP WordPress plugin version 1.3 or earlier. No other products or plugins are listed as affected.
Risk and Exploitability
The CVSS score of 5.9 classifies this as a moderate risk. An EPSS score of <1% suggests that exploitation is unlikely to be widespread, and the vulnerability has not been reported in CISA’s KEV catalog. The stored XSS flaw can be leveraged by any user who can submit content through the plugin’s input forms, without needing elevated privileges or local access. Administrators should treat this as a moderate threat until an official fix is applied.
OpenCVE Enrichment
EUVD