Impact
The flaw is an Improper Neutralization of Input During Web Page Generation vulnerability in the AlphaEfficiencyTeam Custom Login and Registration plugin for WordPress that permits a stored cross‑site scripting (XSS) payload to be persisted and then executed when other users view the affected page. This leads to execution of arbitrary JavaScript in a victim’s browser, potentially enabling session hijacking, defacement, or other malicious actions.
Affected Systems
AlphaEfficiencyTeam Custom Login and Registration plugin for WordPress, all releases up through version 1.0.0.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate risk, while the EPSS score of less than 1% shows a low likelihood of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a remote attacker submitting malicious input via the plugin’s registration or login forms, causing the script to be stored and subsequently rendered in the browsers of any user who views the affected content.
OpenCVE Enrichment
EUVD