Impact
The Astra Widgets plugin contains an improper neutralization of input during web page generation, resulting in a stored cross‑site scripting flaw. The flaw allows an attacker to inject malicious JavaScript that is persisted in the plugin’s configuration or content areas and executed in the browsers of any user who views the affected pages. This can lead to session hijacking, credential theft, defacement, or execution of arbitrary client‑side attacks.
Affected Systems
Brainstorm Force’s Astra Widgets plugin, versions up to and including 1.2.16.
Risk and Exploitability
The CVSS score of 5.9 classifies the vulnerability as moderate, while the EPSS score of < 1% indicates a low likelihood of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Exploitation would most likely occur via the plugin’s administrative interface where an attacker can submit content that is stored and rendered without proper output sanitization.
OpenCVE Enrichment