Impact
The Audiomack WordPress plugin contains a stored XSS flaw that allows input to be saved and later displayed without proper HTML escaping. An attacker who can submit content that the plugin stores and then forces unsuspecting visitors to view that content can inject malicious scripts that execute in the victim’s browser. This can compromise user credentials, hijack sessions, or deface the site.
Affected Systems
The vulnerability affects any WordPress installation running Audiomack plugin version 1.4.8 or earlier. Versions from 1.4.9 onward are not listed as vulnerable and are presumed to have the fix. The flaw resides in the plugin’s core code that processes user‑submitted data.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate‑to‑high severity, and the EPSS score of <1% shows a low current probability of exploitation. The vulnerability is not catalogued in CISA KEV. Exploitation requires submitting malicious input through the plugin’s data entry interface, typically available to authenticated users or authors. Once stored, the malicious payload is delivered to all visitors who load the affected content, making the impact scalable but dependent on hijacked or legitimate content submission.
OpenCVE Enrichment