Impact
The vulnerability is a stored cross‑site scripting flaw in the CM On Demand Search And Replace plugin. Improper neutralization of user input during web page generation allows attackers to inject malicious scripts that will be rendered by browsers when the affected content is displayed. This flaw can enable cross‑site scripting attacks, potentially compromising user sessions, defacing the site, or exfiltrating data. The weakness corresponds to CWE‑79.
Affected Systems
WordPress sites running the CreativeMindsSolutions CM On Demand Search And Replace plugin with version 1.5.2 or earlier are affected. The plugin’s stored XSS can be triggered in any installation that uses the affected plugin, regardless of specific WordPress configuration.
Risk and Exploitability
The CVSS score of 5.9 gives it medium severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at present, and it is not listed in CISA KEV. The most likely attack vector involves an authenticated user inserting malicious payloads into the plugin’s input fields; the injected script is then stored and later rendered to unsuspecting viewers. Proper input validation is required to mitigate this risk.
OpenCVE Enrichment
EUVD