Impact
The vulnerability is a stored cross‑site scripting flaw originating from insufficient input neutralization in the ItayXD Responsive Mobile‑Friendly Tooltip plugin. An attacker who can inject content through the plugin’s input fields can place malicious scripts that will later execute when any user views a page containing that content, potentially stealing credentials or hijacking sessions. The flaw falls under CWE‑79.
Affected Systems
The issue affects the WordPress plugin Responsive Mobile‑Friendly Tooltip by ItayXD, versions up to and including 1.6.6. Any WordPress installation using a version of the plugin in that range is susceptible, regardless of other WordPress components.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation would involve the attacker providing malicious input through the plugin's input fields, resulting in a stored payload that executes for all users who view the affected page.
OpenCVE Enrichment
EUVD