Impact
The REHub Framework plugin in WordPress suffers from an improper neutralization of input that permits stored XSS as identified by CWE‑79. The vulnerability lets an attacker persist malicious script content in the plugin’s data store, which is then rendered unsanitized in web pages, enabling code execution in the context of users who view the affected content.
Affected Systems
The flaw is present in all sizam REHub Framework installations older than version 19.9.9.7, regardless of specific WordPress version. Administrators using these legacy plugin releases should verify the installed build number.
Risk and Exploitability
The CVSS score of 6.5 classifies the issue as moderately severe, yet the EPSS score of less than 1% indicates a low likelihood of active exploitation at present, and it is not listed in the CISA KEV catalog. Exploitation likely requires the attacker to inject payload via a field that the plugin accepts and stores, which can then be viewed by any user accessing pages that display the stored data.
OpenCVE Enrichment