Impact
The Simple Pull Quote plugin for WordPress contains an improper neutralization of input that leads to a stored cross‑site scripting vulnerability. This weakness allows attackers to insert malicious script into quote content that will then be rendered on pages viewed by authenticated and unauthenticated users, enabling cookie theft, session hijacking, or defacement. The flaw is a classic input validation issue, classified as CWE‑79.
Affected Systems
The vulnerability affects the llamaman Simple Pull Quote plugin on WordPress installations where the plugin version is 1.6.3 or older. All environments that have this plugin installed are susceptible, irrespective of WordPress core version.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium severity. The EPSS score is below 1 %, suggesting that exploitation is currently unlikely in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker with access to the plugin’s input fields—such as an administrator or an author with quote editing rights—or via a social‑engineering attempt to trick a user into providing malicious content. While the low EPSS score reduces immediate threat, the stored nature of the flaw means any injected script will persist in the database and affect all site visitors.
OpenCVE Enrichment