Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation flaw that allows an attacker to store malicious script code in the Xpert Tab plugin. Once stored, the code is executed in the browser of any user who views a tab page, which can lead to data theft, session hijacking, or defacement.
Affected Systems
WordPress sites running the ThemeXpert Xpert Tab plugin, versions from the earliest released through 1.3 inclusive. All users who may submit or view tab content are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1 percent shows a very low probability of exploitation in the current environment, and it is not listed in the CISA KEV catalog. Exploitation requires the ability to submit or edit tab content, suggesting that a attacker with write privileges on the site could inject the payload. Once injected, the payload is served to all users accessing the tab, making the impact potentially widespread on a single compromised site.
OpenCVE Enrichment
EUVD