Impact
An input field in the WS Force Login Page plugin is not properly neutralized, allowing an attacker to store malicious scripts that are rendered when a webpage is generated. A stored XSS flaw can lead to session hijacking, cookie theft, defacement, or the execution of arbitrary code in the context of a logged‑in user. The impact is scoped to affected user sessions but can be leveraged for broader social‑engineering attacks if logged‑in users interact with the compromised site.
Affected Systems
Silver Muru’s WS Force Login Page plugin, versions up through and including 3.0.3, is vulnerable. Only these product versions are impacted; newer releases have not been identified as affected.
Risk and Exploitability
The CVSS score of 5.9 denotes a moderate severity, while the EPSS score of less than 1 % suggests a low likelihood of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web request that provides a malicious payload to the plugin’s input field; the stored payload is then served to any user who views the affected page.
OpenCVE Enrichment
EUVD