Impact
The plug‑in fails to properly neutralize user input when generating a web page, allowing an attacker to store malicious scripts that will execute in the browsers of anyone who views the affected content. This type of Cross‑Site Scripting can lead to session hijacking, defacement, or the injection of further malware on the victim site. The weakness is a classic stored XSS flaw identified as CWE‑79.
Affected Systems
The vulnerability affects the WordPress plug‑in "Most And Least Read Posts Widget" from the vendor whiletrue. All versions up to and including 2.5.20 are vulnerable. Users running any of these releases on a WordPress installation are susceptible.
Risk and Exploitability
With a CVSS score of 6.5 the flaw presents a moderate risk, while an EPSS score of less than 1% indicates a very low current likelihood of exploitation. Based on the information, it is inferred that the plug‑in stores malicious code in the database, meaning an attacker only needs to inject input through the plugin’s interface, typically an administrative or content‑editing context. Once stored, the payload would run for every site visitor who triggers the widget, potentially compromising user credentials or delivering further attacks. The flaw has not yet been listed in the CISA KEV catalog but should still be addressed promptly to avoid exploitation.
OpenCVE Enrichment
EUVD