Impact
Based on the description, the flaw allows an attacker to inject malicious scripts that are stored in the database and later rendered on the site’s web pages. Because the input is not properly escaped when generating the HTML response, the injected code will execute in the browser of any visitor who loads the affected page. This can lead to session hijacking, cookie theft, defacement, or delivery of malware. The weakness is a classic Cross‑Site Scripting flaw (CWE‑79).
Affected Systems
WordPress sites that have the Map Categories to Pages plugin by Amit Verma installed, version 1.3.2 or earlier. The problem exists in all installations that contain that plugin up to and including the stated maximum version.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability’s impact is moderate (CVSS 5.9) and the EPSS score of less than 1 % indicates that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog, yet any user with access to the plugin’s input fields can potentially inject malicious payloads. The likely attack vector is an attacker submitting script‑laden data through the plugin’s user interface, which is then reflected to site visitors. Recovery before exploitation requires the plugin to be updated or disabled.
OpenCVE Enrichment
EUVD