Impact
The vulnerability permits an attacker to inject arbitrary script that the application stores and later renders to visitors, potentially enabling session hijacking, data theft, or defacement of the site, thereby compromising user confidentiality and the integrity of the webpage.
Affected Systems
The affected vendor is WPeka; the product is the WP AdCenter WordPress plugin. Versions up to and including 2.6.0 are vulnerable. No further version information is available.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to exploit the plugin’s input fields, injecting malicious script that is stored in the database and later rendered to any visitor, enabling the execution of code in the context of the site visitor's browser.
OpenCVE Enrichment
EUVD