Impact
The vulnerability arises from improper neutralization of input during web page generation, allowing attackers to inject malicious script that is stored and later rendered to users. This stored XSS can lead to cookie theft, defacement, or redirecting visitors to phishing sites, as the content is delivered unfiltered to all users who view the affected page.
Affected Systems
The flaw affects the WordPress Tooltips plugin released by Tomas, versions up to and including 10.9.3, that can be installed on any WordPress website.
Risk and Exploitability
With a CVSS score of 6.5, the severity is moderate, and the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to abuse the plugin’s content storage feature to insert malicious payloads, which will then be served to site visitors.
OpenCVE Enrichment