Impact
An improper neutralization of input flaw allows attackers to inject malicious JavaScript that is stored and rendered on the site’s front end. The stored XSS can be used to deface content, hijack user sessions, or redirect victims to malicious sites, thereby compromising confidentiality and integrity of users’ interactions with the website.
Affected Systems
The vulnerability exists in the WordPress WP Frontend Admin plugin produced by Jose Vega, affecting all releases up to and including version 1.22.7.
Risk and Exploitability
The CVSS score of 6.5 places the flaw in the medium severity range. With an EPSS score of less than 1 % the probability of automated exploitation is low, and the issue is not currently listed in CISA’s KEV catalog. Exploitation would likely require an attacker to manipulate content or configuration settings that are rendered by the plugin, implying that users with administrative privileges or the ability to create/modify frontend pages may be able to inject the harmful payload. No specific CVE‐provided exploit code exists, but the input can be obfuscated as normal content, so detection may be difficult.
OpenCVE Enrichment
EUVD