Impact
The vulnerability arises from improper neutralization of input during web page generation in the Joe Open Currency Converter WordPress plugin. It enables the storage of malicious scripts that are later served to site visitors, leading to execution of those scripts in the context of the visitor’s browser.
Affected Systems
The flaw affects the Open Currency Converter plugin distributed by Joe. All releases through version 1.5.0, including any earlier releases, are vulnerable; installing version 1.5.1 or newer is not affected.
Risk and Exploitability
The CVSS base score of 6.5 indicates medium severity. The EPSS score of less than 1% reflects a low probability of exploitation, and the vulnerability is not listed in CISA KEV. An attacker who can embed a script that the plugin stores and later displays may cause the script to run when other users view the content.
OpenCVE Enrichment