Impact
The vulnerability in Sandor Kovacs Simple Sticky Footer allows a stored cross‑site scripting attack. Serialized user content that is rendered on the page is not properly neutralized, enabling an attacker to inject arbitrary JavaScript into the page. This can lead to session hijacking, credential theft, or malicious redirects for site visitors.
Affected Systems
WordPress sites using the Simple Sticky Footer plugin version 1.3.5 or earlier. Any installation that has enabled the plugin without an update to a fixed release is at risk.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity, and the EPSS score of less than 1% suggests that exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be via the plugin’s input fields that store and render user data; an attacker could submit malicious content that is later served to other visitors.
OpenCVE Enrichment
EUVD