Impact
The vulnerability is an improper neutralization of input during web page generation that allows a stored cross‑site scripting flaw. Unsanitized data submitted through the plugin’s input mechanisms can be stored in the database and later rendered to other users, executing malicious scripts in their browsers. Such an attack can lead to session hijacking, data theft, or further compromise of the site.
Affected Systems
The Top 10 plugin by Ajay for WordPress, affecting all releases up to and including version 4.1.0.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high risk, while the EPSS score of less than 1% suggests that exploitation appears unlikely at this time. The flaw is not listed in the CISA KEV catalog. The most likely attack vector involves submitting malicious script payloads through the plugin’s input fields that are stored and displayed without proper escaping.
OpenCVE Enrichment
EUVD