Impact
The Showpass WordPress Extension contains an improper neutralization of input during web page generation flaw that allows an attacker to store malicious JavaScript code in the site’s content. When the affected pages are rendered, the embedded script executes in the browser context of every visitor, enabling defacement, cookie theft, or session hijacking. The weakness is classified as a stored XSS.
Affected Systems
All releases of the Showpass WordPress Extension from the earliest version through version 4.0.3 are affected. The plugin is distributed by the vendor marcshowpass under the product name Showpass WordPress Extension.
Risk and Exploitability
The severity is moderate with a CVSS score of 6.5. The EPSS score indicates a very low probability of exploitation (<1 %) and the vulnerability is not listed in CISA KEV. The likely attack vector is client‑side, requiring the attacker to inject data that is stored and later rendered, implying that a user with sufficient privileges (e.g., administrator or an account that can submit content) is needed. The impact is confined to defacement or theft of user session data on the target WordPress site, without compromising the underlying server environment.
OpenCVE Enrichment
EUVD