Impact
The flaw is an improper neutralization of user input during web page generation, classified as CWE‑79. It allows a malicious actor to inject JavaScript that will be rendered for any visitor to affected pages, potentially leading to cookie theft, session hijacking, or defacement. The vulnerability is leveraged when the attacker places crafted content into fields managed by the Simple Download Monitor plugin and the content remains stored within the database until displayed.
Affected Systems
WordPress sites that have the Simple Download Monitor plugin installed at versions 3.9.34 or earlier are affected. This includes any instance where the plugin is activated by an administrator or user with sufficient permissions.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need access to the plugin's content entry interface to inject the payload, making the vector dependent on administrative or user-level permissions rather than a purely remote attacker exploiting an exposed endpoint.
OpenCVE Enrichment
EUVD