Impact
The vulnerability is an improper neutralization of input during web page generation that allows stored cross‑site scripting. An attacker who can inject unauthenticated or authenticated data into the Parallax Scrolling Enllax.js plugin can place malicious scripts into page content that will execute when other site visitors view the affected page. This can lead to credential theft, session hijacking, or other client‑side compromise consistent with CWE‑79.
Affected Systems
Affected is the WordPress Parallax Scrolling Enllax.js plugin for snagysandor. Any installation using version 0.0.6 or earlier is vulnerable. The vulnerability list describes versions from n/a through <= 0.0.6.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity, while the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is that a user with the ability to submit content that is stored by the plugin can inject payloads that execute in the browsers of other visitors. Ownership or lack of protective controls means the risk is moderate but the likelihood of attack remains low as no mass‑scale exploitation has been observed.
OpenCVE Enrichment
EUVD