Impact
The WP Tournament Registration plugin for WordPress is vulnerable to stored cross‑site scripting via the *field* parameter in all versions up to 1.3.0 due to insufficient input sanitization and output escaping. This flaw allows authenticated users with Contributor level or higher to inject arbitrary JavaScript that will run whenever any user views the affected page. Based on the description, it is inferred that the injected script could compromise session state, deface content, or exfiltrate data. The weakness is identified as CWE‑79.
Affected Systems
The vulnerability exists in all versions of the WP Tournament Registration plugin provided by the archaeopath organization. Sites running versions 1.3.0 or earlier are at risk unless they upgrade to a later release.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% suggests a very low current exploitation probability. The flaw is not listed in CISA’s Known Exploited Vulnerabilities catalog. An attacker must first be authenticated with Contributor or higher privileges to manipulate the *field* parameter. Once the malicious script is stored, it will execute for any user who visits the affected tournament registration pages, creating a persistent XSS threat that can be leveraged after obtaining contributor access, or possibly through social engineering or compromised administrator accounts.
OpenCVE Enrichment
EUVD