Impact
The Valuation Calculator WordPress plugin contains a stored XSS flaw that allows an authenticated user with Contributor privileges or higher to inject arbitrary scripts through the unsanitized link parameter. When the contaminated page is viewed, the injected script runs in the victim’s browser, enabling attackers to steal cookies, deface content, or execute further malicious actions.
Affected Systems
The vulnerability exists in the reallaunch Commercial Real Estate Valuation Calculator plugin for WordPress, affecting all releases up to and including version 1.3.2.
Risk and Exploitability
The flaw has a CVSS score of 6.4, indicating moderate severity, and an EPSS of less than 1 %, signifying a low likelihood of exploitation in the wild. Because the flaw requires authenticated access at the Contributor level, an attacker first needs valid credentials, but once achieved, the stored payload is able to affect all users who subsequently view the page. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD