Impact
The vulnerability in OTWthemes Post Custom Templates Lite allows attackers to inject malicious script code that is automatically stored and served with subsequent page views. This stored cross‑site scripting flaw can enable attackers to deface content, steal user session cookies, or perform phishing attacks against site visitors. The weakness belongs to CWE‑79, a classic example of input that is not properly neutralized before rendering.
Affected Systems
WordPress sites that have OTWthemes Post Custom Templates Lite installed at version 1.14 or earlier are affected. Any installation using this plugin without upgrading to a patched release is at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating moderate severity, while an EPSS score of less than 1% suggests a low probability of widespread exploitation at present. It is not listed in the CISA KEV catalog. The description does not specify an attack vector; however, it can be reasonably inferred that any user capable of submitting post content to the website could use that interface to inject malicious scripts, which will then be rendered for all visitors.
OpenCVE Enrichment
EUVD