Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw in the WordPress Contextual Related Posts plugin. An attacker can inject malicious JavaScript that runs in the browsers of users who view a page that incorporates content from the plugin. This runtime code can exfiltrate data, hijack user sessions, or facilitate phishing attacks within the victim’s session.
Affected Systems
Any WordPress site using the Ajay Contextual Related Posts plugin version 4.0.2 or earlier is affected. The plugin is installed through the WordPress plugin repository and is used to display related post lists on web pages.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity, while the EPSS score of less than 1% indicate a low likelihood of exploitation based on current evidence, and the flaw is not listed in the CISA KEV catalog. The attack vector is remote: an attacker can craft a URL or embed malicious content in a page that loads the plugin, causing a victim’s browser to execute arbitrary JavaScript when the page is viewed.
OpenCVE Enrichment
EUVD