Impact
The vulnerability is a stored XSS flaw in the WP Rentals theme, arising from improper input neutralization. It allows an attacker to inject malicious scripts that are stored and later rendered in a web page, potentially compromising user session data, defacing content, and executing code in victims’ browsers.
Affected Systems
Affected systems include websites running the WP Rentals theme from WpEstate; all versions up to and including 3.16.1 are potentially vulnerable, and the issue appears to affect all versions prior to 3.16.1 as well.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed active exploits. Likely attack vector is through an administrative interface that accepts unsanitized input, such as rental descriptions or comments, which is stored and later displayed to visitors. If an attacker is able to deliver script payloads, they can coerce unsuspecting users into executing malicious code in their browsers.
OpenCVE Enrichment
EUVD