Impact
The vulnerability in the Smart Related Products plugin allows an attacker to store malicious scripts that are served to site visitors. Such stored XSS can enable session hijacking, credential theft, defacement, or the execution of additional malicious payloads within the victim’s browser. The weakness arises from improper neutralization of user input during page rendering, a classic instance of “Cross‑Site Scripting” as defined by CWE‑79.
Affected Systems
WordPress installations that use the sharkthemes Smart Related Products plugin version 2.0.8 or earlier are affected. Any site that has exposed the plugin’s data entry points or has not updated beyond the stated maximum release is vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity, with the exploit likely limited to browsers that load the compromised page. The EPSS score of less than 1 % suggests a low probability of exploitation in the wild, and the issue is not listed in CISA’s KEV catalogue. Attackers would need to supply input that the plugin accepts and stores—typically through an administrative interface or content creation workflow—before the malicious script becomes visible to site users.
OpenCVE Enrichment
EUVD