Impact
The WP Applink plugin allows stored cross‑site scripting through the title parameter because the input is not properly sanitized or escaped. This flaw enables attackers who have authenticated Contributor or higher access to inject malicious scripts that will run in the browsers of any user who views the affected page.
Affected Systems
All installations of the WP Applink WordPress plugin with versions up to and including 0.4.1 are affected. The plugin is distributed by ejointjp and can be upgraded by site administrators via the WordPress plugin repository.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity vulnerability, and the EPSS score of less than 1% points to an extremely low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been observed in the wild. Attackers must be authenticated with Contributor or higher privileges, implying that the attack vector is internal and depends on the user’s role within the WordPress site. Once authenticated, an attacker can edit or create content with a malicious title, and the payload will execute for every user who accesses the rendered page. Because the vulnerability relies on existing user privileges rather than external network access, exploitation requires administrative control of or access to the WordPress installation.
OpenCVE Enrichment
EUVD