Impact
The vulnerability allows an attacker to store malicious script content that will be executed in a victim’s browser when viewing the affected WordPress site, leading to possible phishing, credential theft, session hijacking and defacement. The flaw resides in improper neutralization of input during web page generation, classifying it as a Stored XSS (CWE-79).
Affected Systems
The flaw affects Robin Cornett Scriptless Social Sharing plugin versions up to and including 3.3.0. Site owners using any of these versions are potentially exposed.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity, and the EPSS score of less than 1% suggests a low likelihood of current exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by injecting malicious payloads into the plugin’s configuration or content fields, which are then rendered without proper sanitization. The likely attack vector is a web form or administrative interface that accepts user input and stores it for later rendering on generating pages.
OpenCVE Enrichment
EUVD