Impact
The vulnerability originates from improper neutralization of input when generating web pages in the SMM API plugin. The flaw allows attackers to inject malicious scripts that are stored in the site’s database and executed whenever the affected page is rendered. This can lead to client‑side compromise, including session hijacking, defacement, or distribution of malware to visitors. The weakness is a classic Injection flaw classified as CWE‑79.
Affected Systems
WordPress sites running the softnwords SMM API plugin version 6.0.31 or earlier are affected. The vulnerability applies to all release versions from the product’s inception through 6.0.31.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity with moderate impact on confidentiality and integrity. The EPSS score of less than 1% reflects a low likelihood of exploitation in the wild, and the vulnerability has not been listed in CISA’s KEV catalog. The likely attack vector is a local or authenticated user capable of submitting content that the plugin processes before rendering. A successful exploit would execute malicious JavaScript in the browsers of other site visitors.
OpenCVE Enrichment
EUVD