Impact
The plugin contains an input handling flaw that fails to neutralize user‑supplied content before rendering it in a web page. Because the data is stored, the vulnerability enables a persistent Cross‑Site Scripting attack that can inject arbitrary JavaScript or other malicious payloads into pages viewed by site visitors. An attacker can use this to hijack user sessions, deface the site, or silently exfiltrate data, thereby compromising confidentiality, integrity, and availability for anyone who accesses the affected pages.
Affected Systems
The flaw exists in the oniswap Mini Twitter Feed WordPress plugin for all releases up to and including version 3.0. WordPress sites that have installed or allow input through these versions are at risk, while systems on newer releases are not affected.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is moderately severe, but the EPSS score of less than 1 % indicates that real‑world exploitation is expected to be rare or low probability. The vulnerability is not yet in the CISA KEV catalog. Exploitability requires a user to input malicious content into the plugin’s data field, which the plugin then stores and later presents without proper sanitization. An attacker can trigger the flaw by inserting script tags or other encoded payloads via the plugin’s input interface and then awaiting page views by other visitors.
OpenCVE Enrichment
EUVD