Impact
The vulnerability is an improper neutralization of input during web page generation in the List Last Changes plugin. It allows a malicious user to inject script code that is stored and later rendered to every visitor of the site. As a stored XSS flaw, an attacker can steal cookies, hijack sessions, deface content, or execute other client‑side attacks. The weakness is identified as CWE‑79.
Affected Systems
The List Last Changes plugin for WordPress, produced by Roland Baer, is impacted in all versions up to and including 1.2.1. Any WordPress site that has an old version of this plugin installed is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, but the EPSS score is below 1 %, suggesting the likelihood of today’s exploit activity is low. Because the flaw is cross‑site scripting, an attacker can introduce malicious content through the plugin’s input fields, and the stored nature means the code executes for all users who view the affected page. The vulnerability is not listed in CISA’s KEV catalog. Likely attack requires the attacker to have at least some form of authenticated access to the plugin’s input interface to inject malicious code, after which all visitors are impacted.
OpenCVE Enrichment
EUVD