Impact
The Telegram for WP WordPress plugin contains a stored cross‑site scripting flaw that arises from insufficient input sanitization and output escaping in its admin settings pages. Authenticated users with administrator‑level permissions or higher can insert arbitrary web scripts that are stored and then executed whenever a visitor loads an affected page. This flaw directly matters for confidentiality, integrity, and availability of site content as it can be used to alter the user experience or deliver malicious payloads.
Affected Systems
The vulnerability affects the Telegram for WP plugin distributed by amir‑mousavi in all releases up to and including version 1.6.1. It is only relevant in multi‑site WordPress installations or in setups where the unfiltered_html capability has been disabled, which permits the insertion of unsanitized HTML.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, while the EPSS score of less than 1% shows a low probability of exploitation. The flaw is not listed in CISA KEV. Based on the description, the likely attack vector involves an authenticated admin+ user accessing the plugin’s settings page to submit malicious script payloads that are then stored and served to site visitors.
OpenCVE Enrichment
EUVD