Impact
The Compact Archives plugin stores unsanitized user input in the generated web pages, creating a stored cross‑site scripting weakness (CWE‑79). An attacker can embed malicious scripts that will be executed in the browsers of site visitors, potentially stealing session cookies, defacing content, or injecting further attacks.
Affected Systems
WordPress sites using Syed Balkhi Compact Archives plugin version 4.1.0 or earlier are affected. The vulnerability is present in all releases up to and including 4.1.0; any site still running these versions is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score of less than 1% suggests a low probability of exploitation in the near term, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the weakness can be triggered via the plugin’s content handling interface, allowing an attacker with permission to add or edit archive content to inject malicious scripts that are stored and later served to site visitors. The attack vector is most likely through legitimate administrative or author access; if the plugin were to accept unsanitized input from public forms, an unauthenticated attacker could potentially exploit the flaw, but this scenario is not explicitly stated in the CVE description.
OpenCVE Enrichment
EUVD