Impact
Improper neutralization of user input in the WP Twitter Button plugin allows an attacker to inject malicious scripts that are stored and later served to all site visitors. This stored cross‑site scripting flaw can lead to cookie theft, unauthorized user actions, or arbitrary code execution in the victim’s browser, compromising confidentiality, integrity, and potentially availability of the web application.
Affected Systems
The vulnerability affects the WordPress plugin WP Twitter Button developed by ruudkok, specifically versions up to and including 1.4.1.
Risk and Exploitability
The flaw carries a CVSS score of 7.1 and an EPSS score of less than 1%, indicating a medium‑high severity but a currently low probability of exploitation. It is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attacker may exploit this weakness by submitting malicious content through the plugin’s input fields, which the plugin stores and later renders to site visitors. An attacker with the ability to submit such content—typically an administrator or a user with publishing permissions—could thereby activate the stored scripts. The low EPSS suggests that widespread exploitation is unlikely at present, yet the potential impact warrants prompt remediation.
OpenCVE Enrichment
EUVD