Impact
The Review Stream plugin, up to version 1.6.7, contains an improper neutralization of input during web page generation, allowing stored cross‑site scripting injection. An attacker who can submit review content can embed arbitrary JavaScript that will execute in the browser of any visitor rendering the stored review. This can lead to credential theft, session hijacking, or defacement but does not provide remote code execution on the server. The weakness is identified as CWE‑79.
Affected Systems
Grade Us, Inc. offers the Review Stream plugin for WordPress. All releases up to and including version 1.6.7 are affected. No other vendor or product is impacted by the documented issue.
Risk and Exploitability
The CVSS score of 5.9 classifies the vulnerability as moderate severity. The EPSS score of < 1% indicates that the likelihood of exploitation in the wild is low, and the vulnerability has not yet been included in CISA's KEV catalog. A typical exploitation scenario would involve a user or attacker injecting malicious script into a review entry stored by the plugin, which then renders when other users or visitors view the review page. No additional authentication or server‑side privileges are required beyond the ability to submit a review.
OpenCVE Enrichment
EUVD