Impact
The vulnerability permits stored cross‑site scripting by improperly neutralizing user input when generating web page content, allowing attackers to inject arbitrary JavaScript that can be executed by site visitors.
Affected Systems
Installations of the WordPress My auctions allegro free edition plugin version 3.6.35 or earlier, maintained by wphocus, are affected. The flaw can be triggered through any user‑submitted content processed by the plugin.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of < 1% shows a very low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a form or interface that accepts user input processed by the plugin; this inference is drawn from the description that the issue is a stored XSS flaw.
OpenCVE Enrichment