Impact
The vulnerability is a stored cross‑site scripting flaw in the Tealium plugin for WordPress. Improper neutralization of input during page generation allows an attacker to inject arbitrary JavaScript that will subsequently run in the browsers of any user who views the affected content. The primary impact is the risk of executing malicious script in victims’ browsers, potentially leading to credential theft, session hijacking, or defacement. The weakness is identified as CWE‑79.
Affected Systems
This flaw affects the Tealium plugin (Tealium:Tealium) for WordPress deployments up through version 2.1.20. All installations that are still running 2.1.20 or earlier, regardless of the release date, are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity. The EPSS score of less than 1 % suggests a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a stored XSS via the plugin’s data entry or configuration interface, meaning that an attacker who can inject data—such as through privileged plugin usage—could place malicious script that will execute whenever visitors load the compromised content. Because the flaw is stored, once an attacker injects the payload it can affect all site users until remediation.
OpenCVE Enrichment
EUVD