Impact
The CVE describes an improper neutralization of user input during web page generation that results in stored cross‑site scripting. The vulnerability resides in the pReya External Markdown plugin and is marked as CWE‑79. Attackers can inject malicious script when the plugin stores and later renders user‑supplied Markdown, potentially allowing the execution of arbitrary code in the context of any visitor to the content area.
Affected Systems
Affected products are WordPress sites that have the External Markdown plugin from vendor pReya installed, specifically version 0.0.1 or earlier. No other versions are listed as affected in the CNA data, and the vulnerability description specifically states that it applies through <=0.0.1.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score of <1% reflects a low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a stored input via the plugin’s content capture mechanism; attackers need the ability to submit Markdown to the plugin to place malicious script, which will then run in the browsers of any user who views the rendered output.
OpenCVE Enrichment
EUVD