Impact
The vulnerability is an improper neutralization of input during web page generation that allows attackers to store malicious scripts in the Kanpress plugin’s content or settings. Stored XSS can lead to credential theft, session hijacking, or defacement when unsuspecting users view affected pages. The weakness aligns with CWE‑79, representing an input validation flaw that executes user‑supplied code on a victim’s browser.
Affected Systems
WordPress sites that install the Kanpress plugin by Isra up to and including version 1.1 are affected. Any WordPress installation using these plugin versions is at risk until the plugin is upgraded beyond 1.1 or replaced.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker to supply malicious content via the plugin’s data entry forms, which is then rendered later as part of the site for all users.
OpenCVE Enrichment
EUVD