Impact
The vulnerability is a stored cross‑site scripting flaw in the Post Rating and Review WordPress plugin. It is triggered by the unchecked 'class' parameter in versions 1.3.4 and older. Authenticated users with Contributor or higher privileges can inject arbitrary JavaScript that is then stored and executed whenever a visitor loads a page containing the injected content. This maps to CWE‑79.
Affected Systems
WordPress sites running the Post Rating and Review plugin from vendor bourgesloic, versions 1.3.4 or earlier.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, while the EPSS score of less than 1% reflects a low likelihood of exploitation in the broader environment. Because the flaw requires authenticated access at the Contributor level, the threat is limited to sites that allow that role to edit ratings or review content. It is not listed in the CISA KEV catalog, and no publicly disclosed exploit has been reported, so the risk is primarily due to potential abuse by existing site collaborators.
OpenCVE Enrichment
EUVD