Impact
The Wishlist plugin for WordPress contains an improper neutralization of input issue that allows a malicious user to embed arbitrary JavaScript into the plugin’s output, giving rise to a stored XSS vulnerability. This flaw is a classic case of CWE‑79 and can lead to session hijacking, credential theft, or arbitrary code execution on a victim’s browser. The impact is confined to the client‑side of the application but can compromise user data and the integrity of the website’s content.
Affected Systems
The vulnerability affects the PickPlugins Wishlist plugin for WordPress, in all releases from the initial launch through version 1.0.43 inclusive. No specific patch level other than the latest release is listed within the CNA data, so any installation running 1.0.43 or older is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not recorded in the CISA KEV catalog. Because the flaw stores malicious scripts in the database, the attack vector is likely via a form or input field that accepts user data; any authenticated or unauthenticated user could inject content, which is then rendered to all visitors of the affected site.
OpenCVE Enrichment
EUVD