Impact
The Next Page, Not Next Post plugin suffers from improper neutralization of user input, allowing stored cross‑site scripting attacks. When a malicious user injects script code into content processed by the plugin, the code is later rendered in web pages viewed by other users, enabling theft of session cookies, defacement, or phishing. This vulnerability is a classic input validation flaw identified as CWE‑79.
Affected Systems
The flaw affects the WordPress plugin “Next Page, Not Next Post” developed by Matt McInvale. All releases from the first available version up to and including 0.3.0 are susceptible. Sites running any of these plugin versions are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% shows a relatively low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation campaigns. Exploitation requires that the attacker be able to inject and store malicious script content in a site using the affected plugin, after which any visitor to the resulting page will execute the code in their own browser.
OpenCVE Enrichment