Impact
The Spoki plugin for WordPress contains a stored cross‑site scripting vulnerability caused by improper neutralization of user input. The flaw allows an attacker to inject malicious scripts that are stored and later executed in a victim’s browser, potentially leading to session hijacking, credential theft, or site defacement.
Affected Systems
Spoki – the Spoki WordPress plugin, versions from no minimum version up to and including 2.17.0. Any WordPress installation that has the vulnerable plugin installed is potentially affected.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate risk. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to supply malicious input that the plugin stores and renders, typically through administrative interfaces or data entry features, and for a victim to later view the affected content. Only a small window of opportunity exists for successful attack.
OpenCVE Enrichment
EUVD