Impact
The vulnerability allows an attacker to store malicious scripts that are rendered in the plugin’s output pages. When users view the affected content, the injected script executes in their browsers, potentially enabling unauthorized actions within the site context.
Affected Systems
Affected products are the WordPress Textmetrics webtexttool plugin from Israpil. Versions up to and including 3.6.2 are vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector involves submitting malicious input through the plugin’s input forms, which is then improperly neutralized and stored for future page rendering.
OpenCVE Enrichment
EUVD