Impact
Improper neutralization of user input in the Woofer696 Dinatur WordPress plugin leads to a stored cross‑site scripting flaw. The flaw allows an attacker to inject arbitrary JavaScript that is rendered to any visitor of the affected site, potentially enabling actions such as cookie theft, session hijacking, or defacement. The weakness is a classic input validation issue identified as CWE‑79.
Affected Systems
Any WordPress site running the Dinatur plugin version 1.18 or earlier is affected. The vulnerability exists in all releases from the plugin's initial version up through 1.18 and is fully contained within the Woofer696 Dinatur plugin.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high severity. The EPSS score of less than 1 percent indicates that the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation likely occurs when an attacker successfully submits malicious content through the plugin’s input fields, which is then stored and displayed to other users. The attack vector is web; an attacker would need to gain access to the site’s administrative interface or exploit a public data entry point that the plugin exposes.
OpenCVE Enrichment