Impact
The DraftPress Team Follow Us Badges plugin contains a stored cross‑site scripting flaw that results from improper neutralization of user input during web page generation. This flaw allows malicious JavaScript to be persisted in the plugin’s output and executed when visitors view affected pages.
Affected Systems
WordPress sites that have the DraftPress Team Follow Us Badges plugin version 3.1.11 or earlier are impacted. The vulnerability applies to all releases of the plugin up to and including 3.1.11.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity for the stored XSS flaw. The EPSS score of less than 1% points to a low likelihood of observed exploitation today, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to inject malicious content via the plugin’s input fields; once stored, the payload is rendered in browsers that access the site, exposing visitors to potential XSS attacks.
OpenCVE Enrichment
EUVD