Impact
The flaw is a stored input‑validation vulnerability that allows an attacker to inject malicious JavaScript into web pages served by the Social Intents live‑chat‑support‑by‑social‑ints plugin. Once stored, the code executes in the browsers of any site visitor, potentially compromising session cookies, defacing the site, or exfiltrating sensitive data. The weakness is classified as a typical Cross‑Site Scripting flaw (CWE‑79).
Affected Systems
WordPress sites that have installed the Social Intents live‑chat‑support‑by‑social‑ints plugin of any version through 1.6.19 are affected. No additional vendor or product information beyond the plugin name is listed, and the plugin is distributed via the WordPress plugin repository.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to submit malicious data through an input field exposed by the plugin, and that the code would execute when any user loads the affected page. Successful exploitation would affect all visitors who view pages rendering the injected content, and would typically be performed remotely once the malicious input is stored.
OpenCVE Enrichment
EUVD