Impact
The WP Crowdfunding plugin accepts user input that is later rendered in web pages without proper encoding, allowing an attacker to embed malicious JavaScript that is stored and served to other users. This Stored XSS flaw can execute arbitrary code in the browsers of anyone who views the affected content, potentially leading to credential theft, session hijacking, or defacement. The weakness corresponds to CWE‑79, an input validation issue.
Affected Systems
The vulnerability exists in Themeum’s WP Crowdfunding plugin for WordPress versions up through 2.1.15. Versions prior to the plugin’s release are not affected, and any deployment using a later release is considered safe. Administrators should identify installations running 2.1.15 or earlier to determine remediation needs.
Risk and Exploitability
With a CVSS score of 6.5, the flaw is rated as medium severity. The EPSS score of less than 1% indicates a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through web interfaces that accept user‑generated content, meaning that an attacker who can submit data—either via an admin account or by exploiting another flaw—could inject script that runs when other users load the stored content.
OpenCVE Enrichment
EUVD