Impact
The vulnerability is a Stored Cross‑Site Scripting flaw that allows an attacker to inject arbitrary JavaScript into content stored by the Passster plugin. When a user views the compromised content, the injected script executes in the context of the victim’s browser, potentially enabling session hijacking, phishing, or defacement. The weakness is classified as CWE‑79, reflecting improper handling of user‑supplied input during web page generation.
Affected Systems
WordPress sites that have the Passster content‑protector plugin version 4.2.18 or earlier installed are affected. The plugin is distributed by WP Chill under the product name Passster.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity impact. The EPSS score of less than 1% shows a very low probability that automated attacks have been observed against this weakness. The vulnerability is not currently listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. Attackers would likely inject malicious content via the plugin’s content‑editing interface, taking advantage of the stored XSS path to compromise any visitor to the infected page.
OpenCVE Enrichment
EUVD