Impact
The vulnerability is an improper neutralization of input during web page generation in the Nasir Uddin Generic Elements plugin, allowing stored XSS. The input is not properly escaped before it is rendered, so an attacker could potentially inject malicious scripts that execute in the browsers of users who view the affected content. This weakness is identified as CWE‑79 and is scored with a CVSS score of 6.5, indicating medium severity.
Affected Systems
This issue affects the Generic Elements WordPress plugin from Nasir Uddin, versions up to and including 1.2.9. Sites that run the plugin are potentially vulnerable.
Risk and Exploitability
The CVSS score indicates a moderate risk, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. An attacker could exploit it by submitting malicious input that is stored and later rendered without proper escaping, causing scripts to run in the browsers of all users who view the content.
OpenCVE Enrichment