Impact
This vulnerability is a Stored Cross‑Site Scripting flaw caused by improper neutralization of input during web page generation. The flaw allows arbitrary script code to be stored by the Include Me plugin and later rendered in browsers when users view affected content. It is classified as CWE‑79.
Affected Systems
The affected product is the Include Me plugin developed by Stefano Lissa. All releases up to and including version 1.3.2 are vulnerable.
Risk and Exploitability
The CVSS score is 5.9, indicating a moderate risk. The EPSS score is less than 1%, suggesting a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker with permission to submit or edit content that the plugin stores, such as a site editor or administrator, who can inject malicious payloads that persist across sessions (inferred).
OpenCVE Enrichment
EUVD