Impact
The vulnerability is an improper neutralization of input during web page generation that allows attackers to inject malicious scripts into pages rendered by the Uncanny Toolkit for LearnDash. This stored XSS flaw can enable credential theft, session hijack, defacement, or other client‑side attacks that compromise the integrity and confidentiality of users interacting with affected content. The weakness is classified as CWE‑79 and can affect any user who loads the compromised content, potentially impacting the entire website's trustworthiness.
Affected Systems
Affected product: Uncanny Toolkit for LearnDash from Uncanny Owl. All releases with a version of 3.7.0.2 or earlier are vulnerable. The issue has been identified for the plugin through the release history up to that version.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests that, while the vulnerability exists, the likelihood of exploitation at this time is low. The flaw is not listed in CISA KEV, but attackers can still exploit it through input fields that store data visible to other users. Likely attack vectors involve a user with privilege to submit data that is then rendered for other visitors. Even without an automated exploit, manual victim targeting is feasible.
OpenCVE Enrichment
EUVD