Impact
This vulnerability allows attackers to inject malicious script into a wordpress plugin that is stored in the site's database. Because the input is not properly escaped, the script is executed when the page is rendered for any visitor. This can result in cookie theft, login hijacking or defacement of the site.
Affected Systems
WordPress sites running Gravitate Automated Tester plugin up to and including version 1.4.5 are affected. Any site that has installed the plugin and uses its data entry features without additional sanitisation is vulnerable.
Risk and Exploitability
With a CVSS score of 5.9 the risk is classified as medium. The EPSS score is below 1%, indicating very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply malicious input through the plugin's storage interface; no elevation of privilege is required beyond access to that interface.
OpenCVE Enrichment
EUVD