Impact
An improper neutralization of input during web page generation in RealMag777 TableOn allows stored cross‑site scripting. When attackers insert malicious code into content that the plugin stores, that code is later rendered in users’ browsers, enabling the attacker to execute arbitrary scripts, steal session cookies, deface the site, or perform other client‑side attacks.
Affected Systems
WordPress sites running the TableOn posts‑table‑filterable plugin by RealMag777 with versions up to and including 1.0.3 are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve normal user or administrator content submissions that are stored by the plugin and later displayed without proper sanitization, giving an attacker the opportunity to embed malicious scripts.
OpenCVE Enrichment
EUVD