Impact
The plugin contains an improper neutralization of input during web page generation, leading to stored cross‑site scripting. An attacker can embed malicious scripts that will be executed in the browsers of any visitor who views the affected content. This can result in session hijacking, credential theft, defacement, or other actions performed on behalf of the victim. The weakness is identified as CWE‑79.
Affected Systems
HT Plugins’ HT Team Member plugin is affected for all releases through version 1.1.7. Sites deploying the plugin on WordPress without updating beyond this version are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score of less than 1 % suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The stored XSS could be triggered when an attacker supplies malicious input via an administrative interface or any input form that the plugin persists and later displays; therefore, the attack vector is inferred to be remote through the web portal, though specifics depend on the site's configuration.
OpenCVE Enrichment
EUVD