Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of input during web page generation in the uSystems Webling WordPress plugin. Because user input is not sanitized, an attacker can embed JavaScript code that is later rendered in the webpages of sites that use the plugin. This allows malicious actors to execute arbitrary scripts in the browser context of anyone who views the affected content, potentially compromising session cookies, defacing pages, or injecting further malicious content.
Affected Systems
Affected publicly: the Webling plugin for WordPress, maintained by uSystems, in all releases through version 3.9.0. No earlier or later versions are listed as vulnerable. Site administrators who have installed Webling 3.9.0 or any earlier release are exposed unless the plugin is disabled or removed.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity; the EPSS score of less than 1% suggests rare exploitation. The vulnerability is not catalogued in CISA’s KEV list. Attackers likely need a web form within the plugin to submit the malicious payload, implying a low to moderate skill requirement and no requirement for system‑level access. If an attacker is able to enact the stored payload, they would gain only client‑side privileges, limiting impact to browsers that view the affected content.
OpenCVE Enrichment
EUVD