Impact
The Sprout Clients WordPress plugin up to version 3.2 contains an improper input neutralization flaw that lets stored data contain malicious script. When a victim views a page that renders the client information, the attacker’s script runs in the victim’s browser, enabling actions such as cookie theft, session hijacking or the display of phishing pages. This flaw is consistent with CWE‑79, the classic Stored XSS weakness.
Affected Systems
Users running the BoldGrid Sprout Clients plugin for WordPress, versions up through 3.2, are affected. The vulnerability was disclosed for the plugin package used by the WordPress ecosystem and applies to all installations that have not been upgraded beyond this boundary.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity with the main impact on confidentiality, integrity, and availability of browser sessions. The EPSS score of <1% indicates a low probability of existing exploitation at the time of assessment, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be via the plugin’s administrative or public interfaces where client data is stored and later rendered, allowing an attacker to inject malicious payloads. Due to the stored nature of the flaw, once the payload is inserted, it will affect all users who access the affected content until the plugin is updated or mitigated.
OpenCVE Enrichment
EUVD