Impact
Data443 Risk Mitigation’s Inline Related Posts plugin contains an improper neutralization of input during web page generation vulnerability; it permits stored XSS, meaning that an attacker could insert malicious scripts that are stored by the plugin and later rendered in site pages. The injected scripts run in the context of any visitor’s browser, which can lead to disclosure of session cookies, credential theft, defacement, or the execution of further malicious actions.
Affected Systems
The vulnerable plugin is "Inline Related Posts" by Data443 Risk Mitigation, Inc. Versions n/a through and including 3.8.0 are affected. Earlier releases are unknown, and no higher‑than‑3.8.0 versions are listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 places it in the medium severity range. The EPSS score of less than 1% indicates a low probability that it will be actively exploited at this time, and the vulnerability is not listed in the CISA KEV catalog. Assuming an attacker can supply malicious input that the plugin stores—likely through administrative or content‑creation interfaces—the stored XSS can be triggered when the content is displayed to site visitors. Consequently, the risk to systems is moderate but can have high impact on the end‑user experience and data security once exploitation occurs.
OpenCVE Enrichment
EUVD