Impact
The Sheet2Site WordPress plugin contains an improper neutralization of input during web page generation, a weakness identified as CWE‑79. This flaw permits attackers to submit malicious script code that is stored and later rendered to any visitor of the affected page, resulting in code execution in the victim’s browser. Because the injected scripts execute in the context of the site, attackers could hijack sessions, steal user data, or spread malware to site visitors.
Affected Systems
WordPress installations running the Sheet2Site plugin at version 1.0.18 or earlier are vulnerable. The issue spans all releases from the initial version up to and including 1.0.18, independent of the WordPress theme or other plugins in use.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity. The EPSS score of <1% indicates a very low likelihood of active exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely a malicious user who can input data into the plugin’s fields; the attacker’s script is stored and then served to authenticated or unauthenticated visitors, enabling arbitrary script execution.
OpenCVE Enrichment
EUVD