Impact
The vulnerability is a DOM‑based cross‑site scripting flaw caused by insufficient neutralization of user data when the WordPress StoryMap plugin renders a page. This allows an attacker to embed and execute arbitrary JavaScript within a victim’s browser window as soon as a vulnerable page is loaded.
Affected Systems
The defect is found in the josepsitjar StoryMap WordPress plugin, affecting all releases up to and including version 2.1. No later versions are listed as affected.
Risk and Exploitability
The CVSS score of 6.5 signifies a moderate impact, while an EPSS score below 1% points to a low probability of widespread exploitation at the time of this analysis. The vulnerability is not present in CISA’s KEV catalog. Based on the description, the likely attack vector involves an attacker delivering malicious input—such as a specially crafted URL or embedded content—that is rendered by the plugin, causing the injected script to execute in the context of any user who views the page.
OpenCVE Enrichment
EUVD