Impact
An improper neutralization of user input in the HT Feed plugin allows an attacker to inject malicious script code that is stored in the WordPress database and subsequently executed when a visitor loads a page containing the injected content. The injected code can be executed in the context of the site, enabling theft of session cookies, defacement, or other client‑side attacks. This vulnerability directly impacts the confidentiality, integrity, and availability of the website as viewed by users.
Affected Systems
The flaw affects the HT Feed plugin developed by HT Plugins for WordPress releases from the earliest available version through version 1.3.0. Any site using this plugin within that version range is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 rates the vulnerability as medium severity, while the EPSS score of less than 1% indicates a very low probability that active exploits are currently observed. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the issue via the web interface by submitting malicious input that is stored in the plugin’s data handling routines, and any authenticated or anonymous visitor viewing the affected content will trigger the payload.
OpenCVE Enrichment
EUVD