Impact
The Abbie Expander plugin for WordPress contains an improper neutralization of user input during web page generation that allows a stored cross‑site scripting vulnerability. An attacker can embed malicious script code into the plugin’s stored data, which is then executed in the browsers of site visitors. This can lead to cookie theft, session hijacking, defacement of the site, or delivery of malware to users.
Affected Systems
The vulnerability is present in the WordPress plugin Abbie Expander from any version through 1.0.1, as supplied by developer Ryan Burnette.
Risk and Exploitability
With a CVSS score of 6.5 the weakness is considered moderate in severity. The EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the plugin’s administrative interface or any input fields that the plugin accepts, where an attacker can inject script payloads that will be stored and later rendered to visitors. Successful exploitation would provide the attacker with the ability to execute arbitrary script in the context of the site’s users.
OpenCVE Enrichment
EUVD