Impact
The Estatik WordPress plugin up to version 4.3.1 contains a DOM‑based XSS flaw caused by improper neutralization of user input during webpage generation. This weakness, classified as CWE‑79, allows an attacker to inject and execute arbitrary client‑side script when a victim loads a crafted page.
Affected Systems
Vulnerable WordPress installations that use Estatik version 4.3.1 or earlier are impacted. Any site that has not upgraded beyond this release is at risk, regardless of PHP or WordPress version.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Likely attack vectors involve an attacker embedding malicious JavaScript in a page that a user visits, requiring the victim to load the crafted page for exploitation to occur.
OpenCVE Enrichment