Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of user input during web page generation. An attacker can inject malicious scripts that will be executed in the browsers of visitors who view the affected content, potentially leading to session hijacking, credential theft, or redirection to phishing sites. The weakness is represented by CWE‑79.
Affected Systems
The affected product is the WordPress Blog Manager WP plugin released by wpdiscover. Versions ranging from the first release up to and including 1.0.5 are vulnerable; the issue was present in every version preceding the release of 1.0.6.
Risk and Exploitability
The CVSS score is 5.9, indicating a moderate severity. The EPSS score of less than 1 % shows a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web‑based, requiring an attacker to craft a payload that the plugin stores and later serves to other users. Once delivered, affected users will experience the injected script within their browsers.
OpenCVE Enrichment
EUVD