Impact
The WP Publication Archive plugin contains an improper neutralization of user input during web page generation that permits stored XSS. Injected scripts are rendered when a page using the plugin is viewed, potentially allowing attackers to run malicious code in the context of the site. Based on the nature of XSS, it is inferred that attackers could use the executed scripts to steal credentials or hijack sessions.
Affected Systems
WordPress sites that are running Eric Mann’s WP Publication Archive plugin version 3.0.1 or earlier are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests exploitation is currently unlikely. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers might exploit the issue by submitting or editing content through the plugin, which would store malicious JavaScript that executes when the content is viewed. No advanced privileges are required; any user who can interact with the affected content is at risk.
OpenCVE Enrichment
EUVD