Impact
Based on the description, the flaw appears to allow improper neutralization of input during web page generation in the devsoftbaltic SurveyJS plugin, permitting the storage and later rendering of arbitrary JavaScript. This flaw allows an attacker to inject malicious code that will execute in the browser of any visitor who loads the affected survey content. The vulnerability is classified as CWE‑79 and enables arbitrary client‑side code execution within the context of the website.
Affected Systems
WordPress sites that use the devsoftbaltic SurveyJS plugin with a version equal to or lower than 1.12.20 are affected. This includes all installations where the surveyjs plugin is present and can render stored survey questions or responses.
Risk and Exploitability
The flaw carries a CVSS score of 6.5, indicating medium severity, and an EPSS score of less than 1 %, reflecting a very low probability of widespread exploitation at present. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires the ability to create or edit survey content, typically through an authenticated user with survey‑management privileges. Once the malicious script is stored, any site visitor who views the survey will have the code executed in their browser.
OpenCVE Enrichment
EUVD