Impact
The Terms Descriptions plugin for WordPress contains a stored cross‑site scripting flaw that allows an administrator to inject arbitrary scripts through the plugin’s admin settings. These scripts are stored in the plugin’s data and executed whenever an affected page is viewed by a user. While the CVE description does not explicitly state the exact downstream effects, it is inferred that an attacker could use the injected scripts to perform actions such as credential theft or defacement, but this is not confirmed by the official statement.
Affected Systems
Any WordPress installation that has the Terms Descriptions plugin with version 3.4.8 or earlier, running a multi‑site network or having the unfiltered_html capability disabled. Single‑site installations with unfiltered_html enabled are not affected.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity; the EPSS score of less than 1 % suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalogue. Exploitation requires administrator privileges and is limited to sites meeting the aforementioned conditions, making the risk relatively constrained but not negligible.
OpenCVE Enrichment
EUVD