Impact
Improper Neutralization of Input During Web Page Generation leads to a Stored XSS flaw in the Theater for WordPress plugin. A malicious user can inject arbitrary JavaScript that is persisted and executed in the browsers of any user who views the affected content. This vulnerability can be leveraged to steal session cookies, hijack user accounts, deface the site, or perform other malicious actions within the context of the site’s privileges.
Affected Systems
Theater for WordPress plugin by Jeroen Schmit, versions from the initial release through 0.18.8 inclusive, are impacted. Any installation running a version equal to or lower than 0.18.8 is vulnerable; the earliest affected release is unspecified (n/a).
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at the current time. The vulnerability is not listed in CISA's KEV catalog. Attackers likely exploit the flaw by submitting malicious content that is stored and rendered to other users, requiring sufficient privileges to add or edit content. Successful exploitation leads to code execution in other users’ browsers.
OpenCVE Enrichment
EUVD