Impact
The flaw is an improper neutralization of input that permits stored XSS in the AWEOS WP Lock plugin. Attackers can inject JavaScript that is then rendered whenever a page containing the plugin data is viewed, enabling cookie theft, credential hijacking, or site defacement. The vulnerability arises from the plugin’s handling of user-provided content during page generation and is captured by CWE‑79. The CVSS score of 5.9 indicates moderate severity.
Affected Systems
All WordPress installations that use the AWEOS WP Lock plugin up to and including version 1.4.8 are affected. The vulnerability does not apply to newer releases of the plugin or to other WordPress plugins.
Risk and Exploitability
The EPSS score is below 1 %, implying a low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Nevertheless, the CVSS score suggests moderate impact if an attacker succeeds. The likely attack vector is through the plugin’s administrative or content entry interface, which stores malicious input for later rendering to site visitors. Prompt remediation is warranted to eliminate the stored‑XSS entry points and protect users.
OpenCVE Enrichment
EUVD