Impact
Stored cross‑site scripting arising from improper neutralization of input during web page generation in the Varnish/Nginx Proxy Caching WordPress plugin enables an attacker to inject malicious scripts that will be executed in the browsers of users who view pages rendered by the plugin. The vulnerability can compromise the confidentiality, integrity, and availability of the site content.
Affected Systems
WordPress sites running Razvan Stanga Varnish/Nginx Proxy Caching plugin version 1.8.3 or earlier are affected. The vulnerability applies across all installations of the plugin up to and including version 1.8.3.
Risk and Exploitability
The CVSS score is 5.9, indicating a moderate impact, and the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalogue. The likely attack vector is through user‑supplied content that the plugin stores without proper sanitization; an attacker could deliver malicious payloads via configuration fields or other input points. Successful exploitation would allow a malicious actor to run arbitrary scripts within the context of the affected websites.
OpenCVE Enrichment
EUVD