Impact
The Inventory Presser plugin for WordPress contains a stored XSS flaw that allows an attacker to inject malicious scripts into pages displayed to other users. This can lead to theft of session cookies, credential leakage, or impersonation of legitimate users. The weakness arises from improperly neutralizing user-supplied input before rendering it, classified as a Cross-site Scripting (CWE-79) issue.
Affected Systems
WordPress sites running the fridaysystems Inventory Presser plugin version 15.2.6 or earlier.
Risk and Exploitability
The CVSS base score of 5.9 indicates moderate risk. The EPSS score of <1 % suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the stored XSS nature, an attacker would need the ability to submit or edit content via the plugin front-end or back-end, which often requires administrative or plugin-author privileges. After compromising a user’s browser, the attacker could execute arbitrary client-side code.
OpenCVE Enrichment
EUVD