Impact
The vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject malicious script into the IP Based Login plugin’s data store. When the affected data is later displayed on a WordPress site, the script executes in the victim’s browser, potentially enabling cookie theft, session hijacking or the injection of additional malicious code. The flaw is specifically identified as CWE‑79.
Affected Systems
The affected product is the WordPress IP Based Login plugin by brijeshk89, versions up through and including 2.4.2. Any WordPress site that has installed this plugin on those or earlier versions is susceptible.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate risk level, and the EPSS score of less than 1% suggests that exploitation is unlikely in the wild. The vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is inferred to involve input fields that the plugin stores and later renders, allowing an attacker to store malicious payloads that run when a user views the content.
OpenCVE Enrichment
EUVD