Impact
The vulnerability arises from improper neutralization of input during web page generation in the wpdrift.no Landing pages and Domain aliases for WordPress plugin, allowing attackers to store arbitrary JavaScript in the database and have it executed when visitors view a landing page or domain alias. This stored cross‑site scripting can enable malicious code to run within the context of the site, potentially affecting confidentiality, integrity, or availability.
Affected Systems
All installations of the wpdrift.no Landing pages and Domain aliases for WordPress plugin with a version equal to or lower than 0.8 on any WordPress site are affected. Users should verify the plugin version and update if necessary.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability requires authenticated user privileges to create or edit content in the plugin. The CVSS score of 5.9 denotes medium severity, and the EPSS score of less than 1% indicates a low probability of widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack path involves an authenticated user—such as a site administrator or contributor—who can create or edit landing page and domain alias content, inserting malicious script that is then rendered to visitors.
OpenCVE Enrichment
EUVD