Impact
The Embed Chessboard plugin (pgn4web) allows an attacker to store malicious script code that will execute in the browsers of any site visitor. The vulnerability is a classic cross‑site scripting flaw where user input is not properly neutralized before being written to the page. Successful exploitation could let an attacker inject arbitrary JavaScript that may perform actions such as stealing session cookies, defacing content, or redirecting users to phishing sites.
Affected Systems
WordPress sites running the pgn4web Embed Chessboard plugin from any version up to and including 3.08.00 are affected. No specific operating systems or environments are mentioned, but the issue exists on all WordPress installations where the plugin is active.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests that exploitation is unlikely but possible. The vulnerability is not listed in the CISA KEV catalog. Because the flaw is stored XSS, it can be triggered by an attacker who can inject content through the plugin’s interface—likely requiring at least permission to add or edit chessboard entries or the ability to run the plugin’s API. Once exploited, the stored malicious script would run automatically in any visitor’s browser when the page loads.
OpenCVE Enrichment
EUVD