Impact
The Football Pool plugin for WordPress contains a stored XSS flaw caused by improper neutralization of user input before it is rendered on a web page. This flaw, classified as CWE-79, allows a malicious actor to inject arbitrary JavaScript that is executed in the browsers of any visitor who views the affected pages.
Affected Systems
All installations of the Football Pool plugin from its earliest build up to and including version 2.12.6 are vulnerable. The plugin is maintained by AntoineH and is used on WordPress sites. No other vendors or products are reported to be affected.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as moderate severity, and the EPSS score of less than 1% indicates a very low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalogue. Because the flaw is stored and rendered in the web page, a remote attacker can trigger the XSS by submitting specially crafted content that the plugin stores and later displays, resulting in arbitrary script execution in the context of site visitors.
OpenCVE Enrichment
EUVD