Impact
The vulnerability is an improper neutralization of input during web page generation that allows stored cross‑site scripting. An attacker can embed malicious scripts into RSS feed content, which will execute in the browser of any user viewing the feed, enabling credential theft or defacement.
Affected Systems
This flaw targets the artiosmedia RSS Feed Pro plugin for WordPress. Versions from any release up to and including 1.1.8 are affected. The CVE payload does not specify a release that contains a fix.
Risk and Exploitability
The CVSS score of 5.9 marks it as moderate severity, and the EPSS score indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited yet. Based on the description, it is inferred that a likely attack vector involves a malicious actor inserting script‑laden entries into the RSS feed through the plugin’s input interface, which are then rendered to all users who consume the feed.
OpenCVE Enrichment
EUVD