Impact
The vulnerability is an improperly sanitized input that enables Stored XSS in the WordPress plugin WP Mailto Links. Attackers can inject malicious scripts into stored data via the plugin's input fields, causing any user that views the affected pages to execute the script. This can lead to session hijacking, defacement, or cookie theft, and is categorized as CWE‑79.
Affected Systems
The issue affects the WordPress plugin WP Mailto Links, produced by Online Optimisation, for all versions up to and including 3.1.4. No other products or version ranges are listed as affected.
Risk and Exploitability
The CVSS base score is 5.9, indicating moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote; an attacker would need to inject a malicious payload through the plugin’s input controls, typically via an administrative or content‑creation interface. Successful exploitation would result in the script executing in the browsers of any user who views the impacted pages, potentially compromising confidentiality or integrity of the site’s data.
OpenCVE Enrichment
EUVD