Impact
The vulnerability is a stored Cross‑Site Scripting (CWE‑79) flaw that allows attackers to inject malicious scripts into web pages generated by the Tan Nguyen Instant Locations plugin. Whenever a user supplies specially crafted input, the plugin saves the data and later renders it without proper neutralization. An attacker could use this to steal session cookies, hijack user accounts, deface content, or execute arbitrary code within the victim’s browser.
Affected Systems
Affecting Tan Nguyen:Instant Locations plugin versions from the earliest release (n/a) up through 1.0. Any WordPress installation using this plugin within that version range is exposed.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate risk. EPSS < 1% shows the likelihood of exploitation is low, and the vulnerability is not listed in CISA KEV. The primary attack vector is inferred to be through normal user input accepted by the plugin, which is then stored and reflected without sanitization, based on the description of a stored XSS flaw. Attackers must identify victims who access pages processed by the plugin to deliver malicious payloads. The impact is limited to client‑side execution but can undermine user trust and facilitate credential theft.
OpenCVE Enrichment
EUVD