Impact
This vulnerability allows malicious JavaScript to be stored within the content of a WordPress site through the WidgetKit plugin when input is not properly neutralized during page rendering.
Affected Systems
WordPress installations that have the WidgetKit plugin installed at version 2.5.4 or earlier, as provided by the vendor Abu Huraira Bin Aman, are affected if they use the plugin to accept input.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity for this stored XSS flaw. The EPSS score of less than 1% suggests a low probability of exploitation at the time of assessment, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via input fields or widget configuration that accepts user‑supplied data; this is inferred from the description that the flaw occurs during web page generation in the plugin.
OpenCVE Enrichment
EUVD