Impact
The vulnerability is an improper neutralization of input during web page generation that allows stored XSS. A malicious actor can inject JavaScript code via inputs handled by the keeros DigitalOcean Spaces Sync WordPress plugin, which is then executed in the browsers of users who view the affected pages. This can lead to session hijacking, credential theft, defacement, or the execution of arbitrary client‑side code. The weakness corresponds to CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
The affected product is the WordPress plugin DigitalOcean Spaces Sync published by Keeross. Versions up through 2.2.1 are vulnerable. The plugin is available for WordPress installations and is typically used to sync files with DigitalOcean Spaces.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests a low probability that this flaw will be actively exploited in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Practical exploitation requires that the attacker be able to input malicious code into a field processed by the plugin; after that, any user who views the affected content will have the injected script executed in their browser. In environments where the plugin handles high‑traffic or highly valuable pages, the risk of observation or exploitation is higher.
OpenCVE Enrichment
EUVD