Impact
This vulnerability arises from improper neutralization of user input in the WP‑Members plugin, allowing malicious code to be stored and later served to visitors. The stored XSS payload executes in the context of a victim’s browser when the compromised content is displayed, potentially enabling session hijack, credential theft, or redirection to malicious sites.
Affected Systems
The issue affects installations of the WP‑Members plugin released by Chad Butler up to and including version 3.5.4.2. All websites that have not upgraded past this release are susceptible if they allow content to be entered via the plugin without proper sanitization.
Risk and Exploitability
The assigned CVSS score of 5.5 indicates a moderate impact, while the EPSS score of less than 1% suggests a low probability of exploitation. Because the vulnerability is stored XSS, the likely attack vector involves submitting a malicious payload through the plugin’s input fields, which then persists and is rendered to any user who views the affected page. The vulnerability is not listed in the CISA KEV catalog, so there is no current evidence of active exploitation in the wild.
OpenCVE Enrichment
EUVD