Impact
The vulnerability described as Improper Neutralization of Input During Web Page Generation (Cross‑Site Scripting) allows an attacker to inject malicious script that is stored in the Accessibility Press plugin, resulting in a stored XSS condition.
Affected Systems
Affecting WordPress plugin Accessibility Press from ikaes (ilogic‑accessibility) for all releases up through version 1.0.2, the flaw means any instance of the plugin that has not been updated beyond that point may be exposed.
Risk and Exploitability
With a CVSS score of 5.9 and an EPSS score of less than 1 percent, exploitation is considered moderate and unlikely to be widely seen but remains a concern, especially if an attacker can create or modify content that the plugin later renders; the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment