Impact
The vulnerability is an improper neutralization of input during web page generation (Cross‑Site Scripting). It allows attackers to embed malicious scripts that are stored within the Pinterest Pinboard Widget plugin and executed when other users view the affected page, potentially leading to session hijacking, defacement, or phishing. The weakness is classified as CWE‑79.
Affected Systems
The affected product is the Pinterest Pinboard Widget plugin from CodeFish, versions from undefined (n/a) up through 1.0.7. All installations running these versions are vulnerable.
Risk and Exploitability
This issue was scored with a CVSS base score of 6.5, indicating moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation at the current time, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the stored XSS if they have the ability to input content via the plugin’s interface, typically through an authenticated user with editing rights. Based on the description, the likely attack vector is an authenticated user who can submit content through the plugin, and the stored payload will execute when any user views the affected content.
OpenCVE Enrichment
EUVD