Impact
The Draft plugin contains an improper neutralization of input during web page generation, which allows stored cross‑site scripting. Malicious data entered through the plugin can be executed in visitors' browsers when the page is rendered. This enables attackers to run arbitrary client‑side scripts, potentially stealing session data, defacing pages, or redirecting users to malicious sites. The weakness is classified as CWE‑79.
Affected Systems
WordPress sites that use the Draft website‑builder plugin from the vendor leeshadle. The flaw exists in all released versions from the plugin’s inception up to and including version 3.0.9. No other vendors or products are affected.
Risk and Exploitability
The CVSS score of 5.9 classifies the vulnerability as medium severity. Its EPSS score of less than 1% indicates a very low likelihood of exploitation at this time, and it is not listed in the CISA KEV catalog. Attackers would likely need administrative access to the WordPress site to submit malicious content through the plugin’s interface, after which the payload would be served to any visitor who loads the affected page.
OpenCVE Enrichment
EUVD