Impact
The vulnerability is an improper neutralization of input during web page generation, allowing attackers to inject arbitrary scripts that are stored and rendered in the plugin’s output. Because the payload is persisted, any user who views the affected page can execute the malicious code, potentially leading to defacement, theft of cookie data, or session hijacking. The weakness is categorized as CWE‑79, a stored cross‑site scripting flaw that directly compromises confidentiality and integrity of data viewed by users.
Affected Systems
Finn Dohrn’s Statify Widget plugin for WordPress, from all releases up through and including version 1.4.6. Users deploying any of these versions through the WordPress plugin repository or other distribution channels are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium‑severity risk, while the EPSS score of less than 1% suggests exploitation is unlikely at the current time. The vulnerability is not listed in the CISA KEV catalog. Attackers would most likely exploit this by submitting malicious input via any form or configuration option that accepts untrusted data and is stored by the widget. Successful exploitation would give the attacker the ability to run scripts in the browsers of any visitor to the affected page, potentially granting access to session state or credentials.
OpenCVE Enrichment
EUVD