Impact
The vulnerability is an improper neutralization of user input that allows stored cross‑site scripting. If an attacker can submit content that is later displayed by the plugin, malicious scripts can execute in the browsers of any site visitor, potentially exposing session data, defacing the site, or furthering other attacks. The flaw directly impacts the confidentiality, integrity, and availability of the web application through client‑side code injection.
Affected Systems
This defect exists in the WordPress Send From plugin developed by Benjamin Buddle. All installed copies of version 2.2 or earlier are affected. No other versions or products are mentioned as impacted.
Risk and Exploitability
The reported CVSS score of 5.9 places the vulnerability in the medium severity range. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of assessment, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need the ability to submit or modify content processed by the plugin; this may require an authenticated user or a configuration that permits guest input, which is a prerequisite inferred from the stored‑XSS nature of the flaw.
OpenCVE Enrichment
EUVD