Impact
The vulnerability is an improper neutralization of input during web page generation that allows stored cross‑site scripting. Attackers can insert malicious scripts that are later rendered when users view affected pages, enabling session hijacking, credential theft, defacement, or other client‑side exploits. The impact is limited to the web client; an attacker cannot directly alter server data or files, but the injected script can compromise users browsing the site.
Affected Systems
The issue affects the WordPress Search by Google plugin from vendor webvitaly. Versions up to and including 1.9 are vulnerable; all releases through 1.9 suffer the flaw. No newer versions are listed as affected.
Risk and Exploitability
With a CVSS score of 5.9 the flaw is considered moderate severity and an EPSS score of <1% indicates a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. An attacker could exploit it remotely by submitting crafted content via the plugin’s interface, which is then stored and displayed to any user visiting the site. No special prerequisites are noted beyond the ability to create or edit content through the plugin.
OpenCVE Enrichment
EUVD