Impact
The Ebook Store plugin contains a DOM‑based cross‑site scripting flaw due to improper neutralization of user input during web page rendering. This allows an attacker to inject malicious JavaScript that runs in the victim’s browser, potentially stealing credentials or hijacking sessions. The weakness is a classic input validation failure, classified as CWE‑79.
Affected Systems
The flaw affects the motov.net Ebook Store WordPress plugin for versions up to and including 5.8009. All WordPress sites that have the plugin installed in these or earlier releases are vulnerable unless the plugin is updated.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score shows a very low exploitation probability of less than 1%. The vulnerability is not yet listed in the CISA KEV catalog, implying no confirmed public exploitation. Attackers can exploit the issue by persuading a user to visit a crafted URL or by manipulating input fields that the plugin processes before rendering. As a DOM‑based XSS, the impact is limited to the victim’s browser context and does not provide remote code execution on the server.
OpenCVE Enrichment
EUVD