Impact
The Easy Flash Embed plugin contains an improper neutralization of input during web page generation that allows an attacker to inject malicious JavaScript that is stored and later executed in the context of other users' browsers. This stored XSS flaw can lead to theft of session cookies, defacement, or execution of arbitrary code within the victim's session, thereby compromising confidentiality and integrity of user accounts.
Affected Systems
The flaw affects the Easy Flash Embed plugin by Vincent Boiardt, versions numbered 1.0 and earlier. WordPress sites that have installed or are running this plugin and have not applied a newer, patched release are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high severity. The EPSS score being less than 1% suggests that the probability of exploitation in the wild is currently low, though the vulnerability is not listed in CISA's KEV catalog. Attackers would need to supply malicious content through the plugin's input fields, which will be persisted and served to other users, making the attack feasible from any user with the ability to add or modify flash embed entries.
OpenCVE Enrichment
EUVD