Impact
The VoucherPress plugin has a stored cross‑site scripting flaw caused by failure to properly neutralize user input during web page generation. Malicious scripts can be stored in the plugin’s data, causing browsers to execute the code whenever a page that displays that data is rendered. The weakness is classed as a typical input handling gap that can lead to client‑side payload delivery.
Affected Systems
Chris Taylor’s VoucherPress plugin versions up to and including 1.5.7, when installed on a WordPress site, are vulnerable. Any site that has the plugin deployed and configured is affected; the vulnerability does not depend on the underlying WordPress version.
Risk and Exploitability
The CVSS score of 5.9 denotes medium severity, while the EPSS indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would generally need to inject data through the plugin’s input mechanisms; this usually requires some level of authenticated access to the plugin’s administrative interface, although the exact privilege level is not specified in the advisory and is therefore an inference.
OpenCVE Enrichment
EUVD