Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation (CWE‑79) that allows a stored cross‑site scripting (XSS) attack. An attacker who can supply input that is persisted by the Aria Font plugin can inject malicious scripts that run in the browsers of anyone who views the affected content, potentially enabling session hijacking, credential theft, defacement, or the deployment of further malware.
Affected Systems
Aria Font, a WordPress plugin from آریا وردپرس, is affected in all releases up to and including version 1.4. Any WordPress site that installs or keeps this plugin at a vulnerable version is at risk.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity. The EPSS score of less than 1 percent suggests that exploitation activity is currently rare. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply input that is stored by the plugin, which likely means they need the ability to submit data through a form or edit a post that the plugin displays. If the site allows unauthenticated users to interact with the plugin, the risk is higher; otherwise, the attacker would need some level of authenticated access.
OpenCVE Enrichment
EUVD