Impact
Improper neutralization of input during web page generation allows an attacker to inject malicious scripts that are stored in the Search Atlas SEO plugin’s interface, enabling the code to execute in the browsers of visitors. This stored XSS flaw can facilitate session hijacking, defacement, or theft of user data and reflects the weakness identified as CWE‑79. The vulnerability primarily endangers the confidentiality, integrity, and potential availability of content displayed to site visitors.
Affected Systems
The impact applies to the Search Atlas Group’s Search Atlas SEO WordPress plugin on all releases up to and including version 2.5.4 (any earlier versions are also affected).
Risk and Exploitability
The CVSS score of 6.5 signals a moderate severity, while an EPSS score of less than 1% indicates a very low probability of exploitation at present, and the flaw is not listed in CISA’s KEV catalog. The vulnerability is a stored XSS that can be triggered through legitimate plugin interaction, likely via the web interface where user‑supplied content is accepted and rendered without proper sanitization. An attacker can exploit this by submitting malicious payloads that are then served to other users accessing the affected content.
OpenCVE Enrichment
EUVD