Impact
The vulnerability is a Stored Cross‑Site Scripting flaw that allows an attacker to inject malicious scripts into the output of the Emma for WordPress plugin. If an attacker can supply data that is stored by the plugin and later rendered in a user's browser, they can execute arbitrary JavaScript in that browser context. This may lead to code theft, cookie hijacking, or other client‑side attacks, but it does not provide a server‑side code execution path.
Affected Systems
The issue affects the WordPress "Emma for WordPress" plugin developed by John Housholder, specifically all releases up through version 1.3.3. WordPress sites that have this plugin installed and which accept user‑supplied data for storage via the plugin are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the WordPress administration interface or any front‑end form that the plugin exposes, where an attacker can inject scripts that are persisted and later executed in visiting browsers. Because the flaw is stored, repeated exploitation may affect many users on the site.
OpenCVE Enrichment
EUVD