Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper input neutralization in the Spiraclethemes Site Library plugin. Its primary impact is that an attacker can inject malicious scripts that execute in a visitor’s browser, enabling session hijacking, credential theft, or defacement. This weakness is categorized as CWE‑79.
Affected Systems
WordPress installations that use Spiracle Themes Spiraclethemes Site Library plugin version 1.5.4 or earlier are affected. Any site that has not yet upgraded beyond 1.5.4 remains vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% reflects a very low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. Attackers typically exploit the flaw by submitting crafted content through the plugin’s editor or other input fields that store user data without proper sanitization. Once injected, the malicious script runs with the permissions of the page visitor.
OpenCVE Enrichment
EUVD