Impact
The vulnerability is an improper neutralization of user input during web page generation, allowing stored cross‑site scripting. A compromised site can deliver malicious code that executes in the browsers of visitors who view affected content.
Affected Systems
The affected product is the Crossword Compiler Puzzles WordPress plugin from Wordwebsoftware. All releases up to and including version 14.5 are vulnerable, while newer versions are believed to contain a fix.
Risk and Exploitability
The CVSS base score is 6.5 and the EPSS score is below 1%, indicating a moderate severity with a low likelihood of exploitation. The issue is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker supplying malicious input through the plugin’s content fields, which is then stored and later rendered in visitor browsers, enabling arbitrary script execution.
OpenCVE Enrichment
EUVD