Impact
The vulnerability allows an attacker to store malicious JavaScript in the WordPress WPCasa plugin, which is then executed in the browser of any user who views the affected content. This Stored XSS flaw arises from insufficient input sanitization during web page generation and can be used to steal session cookies, deface pages, or redirect users to malicious sites.
Affected Systems
The flaw exists in the WPSight WPCasa plugin for WordPress versions up to and including 1.3.2. Site owners using any of these versions are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, yet the EPSS score of less than 1% shows a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to inject code into a location that persists on the site, typically via a form or content field, and then entice other users to view the modified page. Successful exploitation would grant the attacker the privileges of the victim’s browser session, enabling credential theft or defacement.
OpenCVE Enrichment
EUVD