Impact
The vulnerability is an improper neutralization of input during web page generation, resulting in stored XSS. Attackers can embed malicious scripts that are persisted in the plugin’s data and subsequently executed in the browsers of any user viewing pages rendered by the plugin. This can lead to cookie theft, session hijacking, defacement, and other client‑side compromises.
Affected Systems
WordPress users running the chtombleson Mobi2Go plugin version 1.0.0 or earlier are affected. No specific subversions are listed beyond the upper bound; therefore all releases from initial to 1.0.0 are potentially vulnerable. Sites that have not upgraded beyond this release must verify their installed plugin version.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium impact. The EPSS score of less than 1% shows a very low current exploitation probability, and the vulnerability has not yet appeared in CISA’s KEV catalog. The likely attack vector involves submitting malicious input through the plugin’s interface—either from public forms or administrator settings—that is stored and later rendered without proper escaping. Because the flaw is stored, it can affect all visitors who load the impacted pages, making mitigation priority essential for sites that still support legacy versions.
OpenCVE Enrichment
EUVD