Impact
The flaw is an Improper Neutralization of Input During Web Page Generation (CWE‑79) that allows an attacker to store malicious scripts in the Best Restaurant Menu by PriceListo plugin. When the stored data is rendered on the site, the script runs in the browsers of visitors, allowing the attacker to steal session cookies, deface content, or perform unauthorized actions. The impact is that the user’s browser context is compromised.
Affected Systems
WordPress sites that use the Best Restaurant Menu by PriceListo plugin version 1.4.3 or earlier are affected. The vulnerability applies to all installations from the earliest release up to and including 1.4.3, as no earlier version was patched.
Risk and Exploitability
Based on the description, it is inferred that an attacker would need authorized access or a user input area to submit malicious code through the plugin’s input fields, which is then persisted and served to all site visitors. Once executed in a visitor’s browser, the attacker gains the same privileges as that user. The CVSS base score of 6.5 indicates a medium severity. The EPSS score of less than 1% suggests that exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD