Impact
The Mesa Mesa Reservation Widget plugin contains an improper neutralization of input during web page generation that allows a stored XSS flaw to be introduced. If an attacker can supply crafted data that the plugin later renders, the malicious script will execute in the browsers of users who view the affected page, enabling session hijacking, cookie theft, defacement, or other client‑side attacks. The vulnerability is an instance of CWE‑79 – improper input validation leading to XSS.
Affected Systems
WordPress sites that use the gslauraspeck Mesa Mesa Reservation Widget plugin version 1.0.0 or older are vulnerable. Any instance of the plugin that stores user‑controlled data and renders it without proper encoding is affected.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate impact, while the EPSS score of less than 1% suggests that exploitation is currently considered rare. The flaw is not listed in the CISA KEV catalog. Exploitation requires that the attacker can submit or edit content through the plugin’s interface; in these conditions the stored payload will be served to all visitors of the affected page, making it an low‑effort attack for users with content‑submission privileges.
OpenCVE Enrichment
EUVD