Impact
A stored XSS flaw exists in the Imran Emu Logo Slider, Logo Carousel, Logo Showcase, Client Logo plugin. Improper input neutralization allows attackers to inject arbitrary JavaScript that is persisted in the database and executed when other users load affected pages. This can lead to session hijacking, defacement, or delivery of malware to site visitors, representing a typical CWE‑79 vulnerability.
Affected Systems
WordPress sites that have installed Imran Emu’s Logo Slider, Logo Carousel, Logo Showcase, Client Logo plugin version 1.8.1 or earlier are affected.
Risk and Exploitability
The CVSS score of 5.9 reflects a medium severity assessment, and the EPSS score of less than 1 % indicates a low probability of exploitation. The plugin is not included in the CISA KEV catalog. Attackers would likely target sites that expose the plugin’s stored content or that have been compromised for administrative access, injecting malicious payloads through the plugin’s input fields.
OpenCVE Enrichment