Impact
An improper neutralization of input during web page generation allows a DOM‑Based XSS flaw in the Binsaifullah Posten WordPress plugin. The flaw exists in all releases up to and including 0.0.1 and lets an attacker embed malicious JavaScript that runs in the victim’s browser when the page is rendered. The consequence is that attackers can steal cookies, hijack sessions, modify page contents, or perform other client‑side attacks.
Affected Systems
All WordPress installations that include the Binsaifullah Posten plugin, version 0.0.1 or earlier, are affected. The vulnerability is tied specifically to the plugin’s block rendering code and applies to any site that has the plugin activated.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a DOM‑Based XSS that requires the victim to visit a page containing the plugin’s output; an attacker would craft a malicious payload that is executed in the victim’s browser when the page loads.
OpenCVE Enrichment
EUVD