Impact
The vulnerability is an improper neutralization of input that enables a stored cross‑site scripting flaw in the Themify Icons plugin for WordPress. Attackers can inject malicious script code that persists in the site’s database and executes whenever that content is rendered in a user’s browser, allowing the code to run in the context of the website.
Affected Systems
The error affects the Themify Icons plugin by themifyme, versions up to and including 2.0.3. Any WordPress site that has a vulnerable instance of this plugin installed is at risk.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as moderate severity. The EPSS score of less than 1% and absence from the CISA KEV catalog suggest that widespread exploitation is currently unlikely, but the stored XSS is still exploitable if an attacker can submit content to the plugin’s input fields—such as through an administrative interface or any custom content entry point. When the plugin is active, the flaw provides a remote web‑based vector that can cause arbitrary script execution in browsers that visit affected pages.
OpenCVE Enrichment
EUVD