Impact
The Formality WordPress plugin contains a stored cross‑site scripting flaw associated with the align parameter. The flaw arises from insufficient input sanitization and output escaping, allowing an attacker to inject arbitrary JavaScript. When the affected content is viewed, the injected script executes in the visitor’s browser. This corruption is strictly client‑side; the vulnerability does not directly compromise server‑side code or data.
Affected Systems
This issue applies to installations of the Formality plugin supplied by michelegiorgi, running WordPress sites that are using version 1.5.8 or earlier. Upgrading to a newer release that removes the align‑parameter flaw eliminates the vulnerability.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is reported as less than 1 %, suggesting a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is internal, requiring the attacker to be authenticated with Contributor‑level or higher access. Once authenticated, the attacker can use the vulnerable align field to inject and execute scripts, providing client‑side compromise but no direct server‑side impact.
OpenCVE Enrichment
EUVD