Impact
The vulnerability arises from improper input neutralization in the WordPress Volunteer Sign Up Sheets plugin. When data entered into the plugin’s forms is stored without adequate escaping, an attacker can embed malicious scripts that will execute in the browser context of any user who views the developed page. This stored XSS can lead to theft of session cookies, credential hijacking, and defacement, impacting the confidentiality and integrity of the site’s visitors.
Affected Systems
DBAR Productions’ Volunteer Sign Up Sheets plugin is impacted in all releases prior to version 5.5.5. Users who have installed any version older than 5.5.5, including beta or early releases, are vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of less than 1% suggests that current exploitation attempts are very rare, and the vulnerability is not listed in the CISA KEV catalog, meaning there is no evidence of a widespread use. Nonetheless the attack vector is a normal web request to the plugin and requires an attacker to supply malicious input. The threat is real, but it is unlikely to see widespread active exploitation at this time.
OpenCVE Enrichment
EUVD