Impact
Improper input neutralization in Skyword API Plugin causes stored XSS. An attacker can embed malicious JavaScript that is executed whenever a victim views a page served by the plugin, potentially stealing credentials or defacing content. This flaw is classified as CWE‑79.
Affected Systems
Skyword API Plugin for WordPress, versions from the initial release through 2.5.3 are affected. Versions 2.5.4 and newer are not impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not present in CISA’s KEV catalog. Attackers would need to deliver a payload through the plugin’s input mechanisms, which is typically achievable by an authenticated administrator or potentially by any user capable of creating content that the plugin processes. The lack of external constraints lowers the barrier for exploitation.
OpenCVE Enrichment
EUVD