Impact
The Moneytizer plugin contains a DOM‑based cross‑site scripting vulnerability due to improper neutralization of user input during web page generation. An attacker can inject malicious scripts that execute in the context of a victim’s browser, enabling session hijacking, data theft, or defacement. This weakness falls under the input handling class of CWE‑79 and can lead to significant confidentiality and integrity risks for website visitors.
Affected Systems
The vulnerability affects the WordPress "The Moneytizer" plugin 10.0.9 and all earlier releases. Users running any version up to 10.0.9 are impacted, regardless of other WordPress components.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity with a moderate attack complexity. The EPSS score of <1% suggests that automated exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector involves a DOM‑based XSS that can be triggered when a user interacts with the plugin’s user‑generated content input fields. No special privileges or additional software are required for exploitation.
OpenCVE Enrichment