Impact
A stored XSS flaw exists in the icc0rz H5P plugin for WordPress due to improper neutralisation of user input. When crafted content is saved, malicious script is later injected into web pages and runs in the context of any user who views the affected page. This can allow an attacker to steal session cookies, deface the site, or redirect users to malicious destinations, compromising confidentiality and integrity for all users who view the compromised content.
Affected Systems
The vulnerability affects WordPress sites that use the H5P plugin from the icc0rz vendor with versions up to and including 1.16.0. No other product or version information was provided.
Risk and Exploitability
The CVSS score of 6.5 categorises the issue as medium severity. The EPSS score of less than 1 % indicates a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is through the plugin’s content creation interfaces; an attacker who can submit or modify plugin content can inject the malicious script. The stored nature of the flaw means the malicious payload persists until the content is removed or the plugin is upgraded.
OpenCVE Enrichment