Impact
The vulnerability is a stored XSS flaw that allows an attacker to inject malicious scripts into a WordPress site via the WordLift plugin. This flaw falls under CWE‑79 and can lead to the execution of arbitrary JavaScript in the context of an authenticated or unauthenticated user, potentially enabling cookie theft, session hijacking, credential theft, or defacement of the site.
Affected Systems
WordLift plugin for WordPress versions up to and including 3.54.5 is vulnerable. All installations that rely on those versions are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% suggests that exploitation attempts are currently rare. The vulnerability has not been listed in CISA’s KEV catalog. Exploitation requires that an attacker can supply data that the plugin stores and later renders—this is typically achieved through an administrative or content‑editing account or by creating malicious content that is approved and displayed on the site.
OpenCVE Enrichment
EUVD