Impact
This vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of user input during web page generation. The weakness allows an attacker to embed malicious JavaScript that is persisted and subsequently delivered to visitors, enabling client‑side code execution and potential theft of credentials, session hijacking, or defacement. The flaw is classified under CWE‑79 (Improper Neutralization of Input).
Affected Systems
The affected product is the WordPress Gianism plugin authored by Fumiki Takahashi. Versions from the earliest available version through and including 6.0.0 contain the vulnerability. Any WordPress site running these plugin versions is potentially impacted. No specific operating system or WordPress theme is required beyond the plugin itself.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is attackers targeting the plugin’s data storage or configuration interfaces to inject malicious payloads, which are then served to all site users when the plugin renders stored data. Successful exploitation depends on the site’s user base and the effectiveness of front‑end defenses such as content security policies.
OpenCVE Enrichment
EUVD