Impact
The vulnerability is an improper neutralization of input during web page generation, allowing an attacker to inject malicious scripts that will execute in the context of privileged site users. Stored XSS can lead to session hijacking, defacement, or malware delivery. The weakness is identified as a stored Cross‑Site Scripting flaw (CWE‑79).
Affected Systems
Affected systems include WordPress sites that use the Magnigenie RestroPress plugin with a version of 3.2.8.6 or earlier. This encompasses all installations up to the specified maximum version and may affect multiple e‑commerce or restaurant booking platforms built on WordPress.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high impact. The EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. However, stored XSS can still be leveraged by any authenticated or unauthenticated attacker who is inferred to be able to manipulate plugin input fields, making timely remediation a priority.
OpenCVE Enrichment