Impact
The vulnerability is an improper neutralization of input during web page generation, classified as a Stored XSS flaw. Malicious script code can be stored by an attacker and subsequently executed in the browsers of any visitor to the affected WordPress site.
Affected Systems
The flaw affects the Amuse Labs PuzzleMe for WordPress plugin. Any installation of the plugin with a version of 1.2.0 or earlier is susceptible. No specific sub‑versions within 1.2.0 are distinguished; the entire release range up to and including 1.2.0 is considered vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability that this flaw will be currently exploited in the wild, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is user‑generated content that the plugin stores and later renders without proper escaping; an attacker who can create or modify such content can embed arbitrary JavaScript that will be executed when other users view the page.
OpenCVE Enrichment
EUVD