Impact
Improper neutralization of user input in the Popular Posts by Webline WordPress plugin allows attackers to embed and store malicious JavaScript, resulting in stored XSS. This flaw is classified as CWE‑79 and can execute in the browsers of site visitors, potentially hijacking sessions or defacing content.
Affected Systems
WordPress sites running WeblineIndia’s Popular Posts by Webline plugin version 1.1.1 or earlier are affected. The issue applies to all installations of the plugin from the earliest release through the specified maximum version.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the current landscape. The vulnerability is not listed in the CISA KEV catalog. It is inferred that exploitation typically requires an attacker to interact with a vulnerable page or input field within the plugin, after which the stored payload will execute in any visitor’s browser.
OpenCVE Enrichment