Impact
Improper Neutralization of Input During Web Page Generation allows stored XSS in WP Travel Engine. Attackers can inject malicious scripts that are executed when the affected pages are rendered in browsers, leading to arbitrary script execution in the context of legitimate users and potentially enabling session hijacking, defacement, or further exploitation.
Affected Systems
The vulnerable plugin is WP Travel Engine, version 1.4.2 or earlier. The issue affects all builds from earliest release to and including 1.4.2. Administrators should identify installations of this plugin to assess exposure.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity, while the EPSS of < 1% suggests a low probability of exploitation and the vulnerability is not listed in the KEV catalog. The likely attack vector is through input interfaces where attackers can submit malicious data that the plugin stores and later renders to other users.
OpenCVE Enrichment
EUVD