Impact
The plugin contains a stored cross-site scripting flaw in which unsanitized user data can be injected into the public page. This vulnerability allows an attacker to embed malicious JavaScript that will execute in the browsers of visitors who view the construction page. The impact is that attackers can hijack user sessions, steal cookies, deface content, or redirect users to malicious sites. The weakness is classified as CWE‑79.
Affected Systems
The vulnerability affects the Really Simple Under Construction Page plugin for WordPress versions up to and including 1.4.6. Any WordPress site that has not updated beyond 1.4.6 and is using this plugin is vulnerable. Specific version information: all releases from the plugin’s initial release through 1.4.6. No other versions or products are listed by the CNA.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of less than 1% shows a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no known weaponized exploits. Attackers would need to insert a payload into a form or content field that the plugin stores and later renders to users; the vulnerability is stored, so it requires at least one interaction to store the payload, but does not rely on privileged access. Overall risk is moderate; patching should be a priority.
OpenCVE Enrichment
EUVD