Impact
The vulnerability is a stored XSS that occurs when the BMI Adult & Kid Calculator plugin does not properly neutralize user input during page generation. An attacker can inject JavaScript that will run in the browsers of anyone viewing the affected page, potentially allowing theft of session cookies, defacement, or execution of arbitrary actions on behalf of the user.
Affected Systems
The vulnerability affects the WordPress plugin BMI Adult & Kid Calculator, versions from unknown to 1.2.2, which is distributed by Mortgage Calculators. All WordPress sites running this plugin within the affected version range are impacted.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity. The EPSS score of < 1% suggests a low likelihood of current exploitation, and the vulnerability is not listed in CISA's KEV catalog. Attackers would need to supply malicious input that is stored by the plugin, so the attack vector is likely to be user-submitted content. Once stored, browsers rendering the page will execute the injected script, giving the attacker the ability to run arbitrary code in the victim's context. Because the payload is stored, the risk extends to all users who view the affected content.
OpenCVE Enrichment
EUVD