Impact
A stored XSS flaw exists in the Arrow Custom Feed for Twitter WordPress plugin; malicious input can be saved within the plugin’s data store and later rendered in a user’s browser without proper neutralization. This flaw allows the injection of arbitrary JavaScript that can execute in the context of any site visitor, potentially leading to session hijacking, cookie theft, or defacement, as it exploits the weaknesses identified by CWE‑79.
Affected Systems
WordPress sites running Arrow Plugins Arrow Custom Feed for Twitter plugin versions up to and including 1.5.3 are affected. The vulnerability applies to all installations of the plugin in that version range and impacts any user who views pages that display content generated by the plugin.
Risk and Exploitability
The CVSS score of 6.5 categorizes the flaw as moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is a remote attacker gaining access to the plugin’s configuration interface (which requires administrative privileges) to inject malicious script, or injection of payloads that later affect all users who view the plugin’s output.
OpenCVE Enrichment
EUVD