Impact
Improper Neutralization of Input During Web Page Generation in The African Boss Get Cash plugin (versions up to 3.2.3) allows an attacker to store malicious JavaScript in the plugin's database entries. When the plugin renders these entries, the unsanitized input is executed as script in the browser, resulting in a stored XSS flaw. The vulnerability arises from a lack of output encoding (CWE-79) and can be triggered by inserting crafted data into any input that is later displayed to site visitors.
Affected Systems
All WordPress sites that have the African Boss Get Cash plugin version 3.2.3 or earlier are affected. The plugin processes user-supplied data (such as transaction details) and presents it in the front-end without sanitization. The flaw exists regardless of the WordPress core version, so sites of all sizes and hosts remain vulnerable.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity, while an EPSS score of less than 1% indicates a low probability of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote: an attacker submits malicious payload via an input accepted by the Get Cash plugin; the payload is stored in the database and subsequently executed by any user viewing the affected page. Because the payload runs in the victim's browser, it can steal session cookies, deface the site, or redirect users to malicious sites.
OpenCVE Enrichment
EUVD