Impact
Stored cross‑site scripting occurs when the plugin fails to neutralize malicious input before rendering it in web pages. An attacker who can submit data through the plugin can embed JavaScript or other code that will later run in the browsers of visitors to the affected site. This flaw gives attackers the same privileges as the visitor, allowing session hijacking, cookie theft, defacement, and other client‑side attacks. The weakness is catalogued as CWE‑79.
Affected Systems
The risk applies to WordPress sites running the WP CodeUs Ultimate Client Dash plugin in versions from the earliest available up through 4.7. Any site that has not upgraded beyond version 4.7 is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 5.9 indicates moderate severity, and an EPSS score below 1% suggests the likelihood of exploitation is low at this time. The vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires the attacker to supply data that the plugin stores, so the attack vector is likely limited to users with permissions to create or edit content via the plugin. Once stored, the malicious script is served to anyone who views the affected content.
OpenCVE Enrichment
EUVD