Impact
Improper Neutralization of Input During Web Page Generation (CWE‑79) is present in the UiCore Elements plugin for WordPress, allowing stored cross‑site scripting via user supplied data that is not properly escaped when rendered. An attacker who can inject malicious script can execute arbitrary JavaScript in the browsers of any visitor who views the affected content, potentially enabling cookie theft, session hijacking, defacement, or the execution of malicious payloads in a browser context.
Affected Systems
The vulnerability exists in all releases of the uicore-elements plugin up through version 1.3.4. WordPress sites that have installed any version of this plugin within that range are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The issue is not listed in the CISA KEV catalog. Attackers would likely exploit it by submitting malicious content through the plugin’s input fields, which is stored and later displayed to site visitors. No additional conditions are required beyond ability to inject data that is rendered to other users.
OpenCVE Enrichment
EUVD