Impact
The flaw is an inappropriate neutralization of user input that allows stored cross site scripting within the Themify Audio Dock plugin. An attacker who can type content into the plugin’s fields can inject malicious JavaScript that is later rendered on the site’s audio dock page. When a visitor loads the page, the script executes in the visitor’s browser, enabling cookie theft, session hijacking, site defacement or redirection to phishing sites.
Affected Systems
Any WordPress installation that has the Themify Audio Dock plugin version 2.0.5 or earlier from themifyme is affected. The vulnerability operates regardless of the visitor’s role, as the stored payload is displayed to all users who view the dock page.
Risk and Exploitability
The CVSS score of 5.9 reflects moderate severity for a stored XSS. An EPSS score of less than 1 percent indicates a low probability of an active exploitation script currently. The vulnerability is not listed in CISA KEV. Attackers would need to inject malicious content via the plugin’s input interface; after insertion the payload is served to every site visitor, limiting impact to client‑side compromise but potentially leading to other privilege escalation if combined with additional weaknesses.
OpenCVE Enrichment
EUVD