Impact
Improper neutralization of input during web page generation in the cartpauj User Notes plugin allows a stored cross‑site scripting flaw. An attacker can inject malicious script payloads into notes, which will then be executed in the browsers of any user who views that note. This can lead to session hijacking, credential theft, or defacement of the site because the code runs in the context of the visiting user’s session.
Affected Systems
Cartpauj’s User Notes plugin, versions from the initial release through 1.0.2, is affected. Any WordPress site that hosts this plugin and therefore allows users to create or edit notes using an unfiltered input field is vulnerable.
Risk and Exploitability
The CVSS score of 5.9 classifies this as a moderate‑risk vulnerability. The EPSS score of less than 1 % indicates that real‑world exploitation is currently very unlikely. It is not listed in the CISA KEV catalog. Attackers would need to have access to the note creation or editing interface; otherwise they cannot inject payloads. Consequently, the risk is moderate with low probability of exploitation under current conditions.
OpenCVE Enrichment
EUVD