Impact
The OpenSheetMusicDisplay WordPress plugin allows a stored XSS when the className parameter is not sanitized, enabling an attacker with Contributor or higher access to inject JavaScript that executes whenever a user loads a page that references the malicious className. This stored payload can modify displayed content or steal sensitive information, falling under CWE‑79.
Affected Systems
Affected systems include the opensheetmusicdisplay plugin deployed in WordPress installations running any version up to and including 1.4.0. Any WordPress site that has installed that plugin and has users with Contributor or higher level privileges is potentially impacted.
Risk and Exploitability
The CVSS score of 6.4 signals a medium severity, and the EPSS score of less than 1% indicates a low probability of widespread exploitation at the moment. Because the vulnerability requires authenticated access, the risk is confined to sites where attacker accounts exist or could be compromised; still, without a KEV listing the exploit reference is limited. Nonetheless, an attacker can execute arbitrary JavaScript in the context of site visitors, posing a risk to confidentiality and integrity.
OpenCVE Enrichment
EUVD