Impact
The vulnerability is an improper neutralization of input during web page generation in the Zoefff Werk aan de Muur plugin, which allows stored cross‑site scripting. Malicious scripts injected via the plugin can persist indefinitely and execute in the browsers of any user who views the compromised content.
Affected Systems
WordPress plugin Werk aan de Muur, developed by Zoefff, any version 1.5 or earlier.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low expected exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires inserting malicious content that the plugin stores and later renders without proper sanitization, potentially affecting all users who view the affected page.
OpenCVE Enrichment