Impact
The Posts By Tag plugin fails to properly encode user supplied tag data, enabling an attacker to embed malicious JavaScript that is executed when visitors load tag‑based pages. This stored XSS can lead to cookie theft, session hijacking, defacement, or the delivery of additional malware, compromising user confidentiality, integrity, and availability. The weakness is classified as CWE‑79.
Affected Systems
All WordPress installations that use the Posts By Tag plugin by Sudar Muthu with a version up to and including 3.2.1 are affected. Versions newer than 3.2.1 are not impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests exploitation is currently considered unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the most probable attack vector is an attacker who can create or edit a tag and inject script code that is stored and rendered in the plugin’s output. Because the exploitation requires write access to tag metadata, an attacker must first obtain permission to edit tags, either through a compromised user account or by exploiting another vulnerability that grants tag editing authority.
OpenCVE Enrichment