Impact
The vulnerability admits attackers to inject arbitrary JavaScript that is stored within WordPress pages rendered by the ThirstyAffiliates plugin. The stored cross‑site scripting can execute in the browsers of any user viewing the affected content, potentially leading to session hijacking, credential theft, defacement, or further malicious payload delivery. The flaw is an input validation failure identified as CWE‑79.
Affected Systems
WordPress installations that include the ThirstyAffiliates plugin from Blair Williams with any release up to and including 3.11.8 are affected. Any site that has installed the plugin during that version range is vulnerable; later plugin releases contain the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk if the flaw is successfully leveraged. The EPSS of <1% suggests that exploitation is uncommon at present, and the vulnerability is not present in CISA’s KEV catalog. The likely attack vector is inferred to be a process that writes user‑supplied data—such as plugin configuration fields—without proper sanitization, which then persists and is displayed to visitors.
OpenCVE Enrichment