Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject malicious JavaScript into webpages rendered by the oik WordPress plugin. When a user views a page or interacts with a part of the plugin, the injected script executes in the victim’s browser, potentially stealing session cookies, defacing content, or delivering phishing payloads. The weakness is a classic input‑neutralization failure classified as CWE‑79.
Affected Systems
The oik plugin for WordPress, developed by bobbingwide, is affected in all releases up to and including version 4.15.3. Users running these versions are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is below 1 %, suggesting the probability of exploitation in the near term is low. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a crafted URL or user‐controlled parameter that the plugin processes without proper escaping; the vulnerability is client‑side and does not require authentication, so any user who visits a affected page could be impacted.
OpenCVE Enrichment