Impact
Improper Neutralization of Input During Web Page Generation leads to a DOM‑Based Cross‑Site Scripting vulnerability in the WordPress User Specific Content plugin. An attacker that can supply crafted input seen by a victim user may execute arbitrary JavaScript in that victim’s browser, enabling session hijacking, credential theft, or defacement of the page.
Affected Systems
The plugin "User Specific Content" developed by Bainternet is affected for all releases from the earliest version through 1.0.6. WordPress sites running any of these versions are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 places this flaw in the medium range, and the EPSS score of < 1% indicates a very low likelihood of exploitation today. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to supply malicious content that is rendered by the plugin, typically via a URL or form field, and a victim would have to view the affected page for the injected script to run. Defenses include whitelisting inputs and enforcing a strict Content Security Policy.
OpenCVE Enrichment