Impact
This vulnerability arises due to inadequate sanitization of the widgetId parameter in the Personizely plugin, enabling authenticated users with Contributor privileges to store malicious scripts. When a page containing the injected widgetId is viewed, the browser executes the embedded script, which may lead to unintended behavior. It is identified as a CWE‑79 type problem.
Affected Systems
WordPress installations using the Personizely A/B Testing, Personalization, Popups & CRO plugin up to and including version 0.10 are vulnerable. The vendor is personizely, and the affected product is the Personizely plugin.
Risk and Exploitability
The CVSS score is 6.4, indicating moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present and the vulnerability is not listed in the CISA KEV catalog. An attacker would need to be an authenticated Contributor or higher and would exploit the flaw by submitting a malicious widgetId value through the plugin’s interface; execution is triggered when any site visitor loads the affected page.
OpenCVE Enrichment
EUVD