Impact
The Norse Rune Oracle Plugin does not neutralize user input before storing and subsequently rendering it, which allows an attacker to embed malicious scripts that execute in the browsers of users who view affected pages. This flaw is a CWE‑79 Cross‑Site Scripting vulnerability. An attacker can therefore steal credentials, modify page content, or perform other malicious actions on the victim’s behalf.
Affected Systems
Any WordPress site running WP CMS Ninja Norse Rune Oracle Plugin up to and including version 1.4.3 is vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 signifies moderate severity, while the EPSS score of less than 1% indicates a low current likelihood of exploitation. The most probable attack vector is through the plugin’s input interface, where payloads are stored and later displayed. The vulnerability is not listed in the CISA KEV catalog, but because the stored payload can be executed by any visitor, it remains attractive for targeted attacks.
OpenCVE Enrichment
EUVD