Impact
This vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject malicious script into web pages generated by the Verowa Connect plugin. Successful exploitation could lead to defacement, theft of user session tokens, or execution of arbitrary client‑side code in the context of affected users, impacting confidentiality, integrity, and availability of the website content.
Affected Systems
The flaw exists in the Verowa Connect plugin from Picture‑Planet GmbH for all versions up to and including 3.2.3. Any WordPress installation that has installed this plugin at or below that version is susceptible to the attack.
Risk and Exploitability
With a CVSS v3.1 base score of 6.5, the vulnerability is considered medium severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is through a web request that renders plugin data, inferred from the stored nature of the XSS. An attacker may need the ability to write data that will be later displayed to authenticated or unauthenticated users. No specific preliminary conditions are mentioned in the description.
OpenCVE Enrichment
EUVD