Impact
The vulnerability is an improper neutralization of input during web page generation that enables stored XSS within the History Log by click5 plugin. Malicious scripts can be persisted in log entries and executed when a site visitor loads a page that displays the log, potentially leading to credential theft, session hijacking, or defacement. The weakness is classified as CWE‑79.
Affected Systems
WordPress sites using the History Log by click5 plugin version 1.0.13 or earlier are affected. Any site that has not yet upgraded beyond 1.0.13 and has the plugin installed is vulnerable to this issue.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of < 1% reflects a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers could exploit this by creating or manipulating log entries; the resulting JavaScript would run in browsers of users who view the log page, potentially compromising confidentiality, integrity, or availability of site content.
OpenCVE Enrichment
EUVD