Impact
The vulnerability allows an attacker to inject malicious scripts that are stored within the WordPress site and executed whenever visitors load affected gallery pages. This can lead to session hijacking, credential theft, defacement, or spreading malware, compromising the confidentiality and integrity of any user who views the gallery content.
Affected Systems
The flaw exists in the WP Chill Gallery PhotoBlocks plugin for WordPress, affecting all releases from the first version through version 1.3.1 inclusive. Any site running an affected instance of this plugin without a newer patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity that allows remote exploitation via stored data. The EPSS score of less than 1% suggests that the exploitation probability is currently very low. The vulnerability is not listed in CISA's KEV catalog, further implying limited widespread use. Based on the description, the likely attack path involves an attacker who can authenticate as a site editor or administrator and add malicious gallery content, which is then rendered to all visitors.
OpenCVE Enrichment
EUVD