Impact
The flaw is an improperly neutralized input during web page generation, allowing stored XSS in the WP AutoKeyword plugin. An attacker can inject malicious scripts that execute in the browsers of visitors who view content generated by the plugin. Such scripts could steal credentials, hijack sessions, deface the site, or trigger any client‑side action.
Affected Systems
The vulnerability affects the EXEIdeas International WP AutoKeyword WordPress plugin, version 1.0 and all earlier releases. Any WordPress site running one of those versions is at risk.
Risk and Exploitability
The CVSS score of 7.1 classifies this as high risk, while an EPSS score of less than 1% suggests a low current probability of exploitation. The flaw is not listed in the CISA KEV catalogue. Attackers can exploit the stored XSS by inserting payloads into the plugin’s keyword or configuration inputs, typically requiring access to the plugin’s administration area or the ability to submit content that the plugin subsequently renders. The impact is confined to browsers of all users who view the affected content.
OpenCVE Enrichment
EUVD