Impact
Improper neutralization of input during web page generation allows stored XSS that can execute arbitrary scripts when users view affected pages, potentially compromising session integrity and enabling data theft.
Affected Systems
All WordPress installations using the yonifre Lenix scss compiler plugin version 1.2 or earlier.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, meaning no known large‑scale exploitation campaigns have been reported. Based on the description, it is inferred that attackers could exploit the flaw by submitting malicious SCSS content through the plugin’s administrative interface, which is then stored and rendered without proper escaping. Once an attacker succeeds, any user who views the compromised page will execute the injected script. The recommendation is to treat the issue as a moderate risk until the plugin is patched, as the risk may increase if the site has exposed the plugin’s interface to non‑authenticated users.
OpenCVE Enrichment
EUVD