Impact
An older version of the WP Notes Widget plugin for WordPress fails to properly neutralize user‑supplied content that is rendered on web pages. This flaw allows an attacker to inject malicious JavaScript that runs in the context of the page, leading to a DOM‑based cross‑site scripting vulnerability. While the description does not list specific attack scenarios, the nature of the flaw means a compromised script could hijack a user’s session, steal cookies, deface the site, or redirect visitors to malicious sites.
Affected Systems
Steve Puddick’s WP Notes Widget plugin for WordPress is vulnerable. Any instance of the plugin that has a version of 1.0.6 or earlier is impacted. The vulnerability is documented for all releases from the initial version up to and including 1.0.6.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of <1% suggests a very low probability of exploitation in the wild at the time of analysis. The vulnerability is not in the CISA KEV catalog. Based on the description, the likely attack vector is a web‑based XSS triggered by unsanitized user input. An attacker with access to a note entry or who can influence the content displayed by the plugin can inject malicious scripts. Because the flaw is DOM‑based, it requires a victim to visit a crafted page, but no special privileges are needed on the server.
OpenCVE Enrichment
EUVD