Impact
This vulnerability results from improper neutralization of input during web page generation, allowing an attacker to inject malicious scripts that are executed in the victim’s browser when the Author WIP Progress Bar plugin processes user input. A successful attack could enable session hijacking, credential theft, defacement of the site, or the execution of arbitrary client‑side code without the user’s consent.
Affected Systems
The affected system is the WordPress plugin Author WIP Progress Bar by Alan Petersen, versions from the first release through and including 1.0. Any WordPress installation that has this plugin installed and active up to version 1.0 is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests that, at present, the likelihood of public exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply malicious input that is rendered in the plugin’s output, likely via crafted URLs or form submissions that the plugin does not properly sanitise. Because the flaw is DOM‑based, it is exploitable only within the user’s browser context and does not require elevated privileges on the server.
OpenCVE Enrichment
EUVD