Impact
This vulnerability arises from improper neutralization of input during web page generation, allowing an attacker to inject malicious scripts that are stored in the plugin’s database. When site visitors load the affected pages, the scripts run in their browsers, potentially stealing credentials, defacing content, or executing other malicious actions.
Affected Systems
The issue affects the WordPress Ebook Store plugin developed by motov.net, applicable to all releases from the earliest available version through version 5.8008.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity, and the EPSS score of less than 1% implies a low probability of active exploitation. The vulnerability is not listed in CISA's KEV catalog. Attackers would need to submit malicious input through the plugin’s stored data fields, which the plugin fails to sanitize, making the attack vector web‑based and exploitable by users who can submit content to the site.
OpenCVE Enrichment
EUVD