Impact
Improper neutralization of input during web page generation allows attackers to inject JavaScript that is stored and later executed in users’ browsers. This stored XSS can lead to session hijacking, credential theft, or defacement of the site, thereby compromising the confidentiality and integrity of data accessed through the affected application.
Affected Systems
The vulnerability affects the Jordy Meow Code Engine plugin for WordPress, versions from the first release through 0.3.2. All WordPress sites running these plugin versions are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is less than 1 %, suggesting a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through legitimate plugin inputs that are not properly sanitized, allowing an attacker to store malicious script payloads that are rendered in future page loads.
OpenCVE Enrichment
EUVD