Impact
This vulnerability results from improper neutralization of user input when generating the Video Gallery by Huzzaz web pages, allowing an attacker to store malicious scripts. Affected gallery entries can carry scripts that execute whenever a visitor views the gallery, potentially leading to session hijacking, defacement, or credential theft. The weakness is a classic Cross‑Site Scripting flaw classified as CWE‑79.
Affected Systems
The Video Gallery by Huzzaz plugin for WordPress, versions up to and including 10.5, is affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the gallery’s content creation interface, where an attacker can inject script code that is then rendered for any page viewer.
OpenCVE Enrichment