Impact
The vulnerability is a stored cross‑site scripting (XSS) flaw that originates from improper neutralization of input during web page generation. Attackers can inject malicious scripts that are saved to the database and executed when other users view pages that display the data. The weakness is classified as CWE‑79.
Affected Systems
The Team Showcase plugin by Themepoints, with affected releases from the initial version through version 2.9, frames WordPress sites that use the plugin.
Risk and Exploitability
With a CVSS score of 6.5 the flaw presents moderate‑to‑high severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the most likely attack vector is through submittable fields within the plugin that store input without proper sanitization, allowing an attacker to inject code that runs in the browsers of site visitors.
OpenCVE Enrichment