Impact
Improper neutralization of user input during web page generation allows a stored XSS vulnerability in the WebberZone Snippetz add‑to‑all plugin. An attacker who can inject malicious scripts through the plugin’s input fields can have them executed in the browsers of all site visitors, enabling cookie theft, session hijacking, defacement, or execution of arbitrary code. The weakness is a classic client‑side injection flaw identified as CWE‑79.
Affected Systems
WordPress installations that use the WebberZone Snippetz add‑to‑all plugin version 2.1.1 or earlier are affected. The issue applies to all earlier releases, with no lower bound specified.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the ability to add or modify content through the plugin’s interface, after which the attacker’s script will be rendered in the site’s front‑end for any visitor. Attackers can embed malicious payloads that execute in the user’s browser, potentially compromising user sessions and data.
OpenCVE Enrichment
EUVD