Impact
Premmerce User Roles stores unsanitized data and is vulnerable to stored cross‑site scripting. An attacker can inject malicious scripts that are rendered when other site visitors load pages containing the compromised content. Depending on the user context, this flaw can lead to cookie theft, session hijacking, defacement, or redirection. The weakness is reflected in CWE‑79 and has a CVSS score of 5.9, indicating moderate severity.
Affected Systems
Any WordPress site using the Premmerce User Roles plugin up to and including version 1.0.13 is affected. The issue applies to all installations that have not upgraded beyond that version.
Risk and Exploitability
The CVSS score of 5.9 classifies the flaw as moderate; the EPSS score of less than 1 % suggests that exploitation attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog. However, the flaw can be triggered through ordinary user interactions with the plugin’s input fields, meaning an attacker who can submit data via the affected interface could embed and persist malicious scripts. While the impact is limited to the affected plugin’s scope, a compromised script can affect all users who view the page.
OpenCVE Enrichment