Impact
Store XSS in the Append extensions on Pages plugin allows attacker to embed malicious scripts that execute in the browsers of anyone who views the affected page. This can lead to session hijacking, credential theft, defacement, or malware distribution. The weakness is a classic input validation flaw identified as CWE‑79.
Affected Systems
The vulnerability affects the WordPress plugin Suresh Kumar Mukhiya Append extensions on Pages for all releases from the initial release through version 1.1.2. Any WordPress site running the plugin at these versions is impacted.
Risk and Exploitability
The CVSS score of 5.9 indicates medium severity. The EPSS score of less than 1 % suggests a low exploitation likelihood at present, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw is stored XSS, an attacker can embed a payload that will run when a victim visits the impacted page, typically requiring the victim to legitimately view the page via the web browser.
OpenCVE Enrichment
EUVD