Impact
The PE Easy Slider plugin for WordPress contains an improper neutralization of input flaw that enables stored XSS. Modifications to slider content are not adequately sanitized, allowing an attacker to inject script that is later rendered on the site for any visitor. The injected code can steal user credentials, deface the website, or serve as a vector for phishing or malware distribution.
Affected Systems
WordPress sites that have DJ‑Extensions.com PE Easy Slider version 1.1.0 or earlier installed are affected. The vulnerability is present in all releases up through version 1.1.0 and does not affect newer versions that have applied the fix.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS < 1% suggests a low likelihood of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could create malicious slider content through the plugin’s administrative interface, and the payload would be stored and served to all site visitors.
OpenCVE Enrichment
EUVD