Impact
Improper neutralization of input during web page generation in the Epeken All Kurir plugin allows stored cross‑site scripting. An attacker can store malicious scripts that will execute in the browsers of anyone who views the affected content.
Affected Systems
WordPress sites running the Epeken All Kurir plugin of any version up to and including 2.0.6 are vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at this time. The flaw is not listed in the CISA KEV catalog. Exploitation requires the ability to submit data that is stored and then rendered by the plugin.
OpenCVE Enrichment
EUVD