Impact
The vulnerability is an improper neutralization of input during web page generation, allowing an attacker to store malicious script payloads in the WordPress AnyClip Luminous Studio plugin. When a victim views the affected content, the injected script executes in the victim's browser, enabling session hijacking, defacement, or the delivery of additional malware. The weakness is a stored XSS flaw and is categorized as CWE‑79.
Affected Systems
AnyClip Luminous Studio, a plugin for WordPress, is affected in all releases up to and including version 1.3.3. The issue is present in the anyclip‑media component, which is commonly used within WordPress sites that host video content.
Risk and Exploitability
The CVSS base score of 5.9 indicates a medium impact, and the EPSS score of less than 1% means the likelihood of exploitation in the wild is low. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been documented. A likely attack vector involves an adversary submitting malicious content through the plugin’s storage features, which is then rendered on the site for all users.
OpenCVE Enrichment
EUVD