Impact
The listed issue is a Stored Cross‑Site Scripting vulnerability in the CodeFlavors Featured Video for WordPress – VideographyWP plugin. The plugin fails to properly escape user‑supplied input when generating web pages, which can allow an attacker to inject arbitrary JavaScript that executes in the browsers of visitors viewing the affected page.
Affected Systems
The vulnerability affects CodeFlavors Featured Video for WordPress – VideographyWP plugin versions 1.0.18 and earlier. WordPress sites that have this plugin installed and have not updated beyond that version are potentially impacted.
Risk and Exploitability
The CVSS score of 6.5 shows moderate severity, while the EPSS score of less than 1% suggests low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV, indicating no confirmed widespread attacks. The likely attack vector is inferred to be an attacker with the ability to submit or modify video metadata through the plugin’s administrative interface or via malicious user input that the plugin accepts, allowing the attacker to store malicious script that will execute in browsers of users viewing the affected page.
OpenCVE Enrichment