Impact
The StreamWeasels Twitch Integration plugin for WordPress stored malicious code within the data‑uuid attribute, which is rendered on every page load. An authenticated user with contributor or higher privileges can inject arbitrary JavaScript that will execute in the browsers of anyone who visits the affected page. The injected script can steal session cookies, deface content, or perform other client‑side attacks, representing a typical stored XSS (CWE‑79).
Affected Systems
WordPress sites running StreamWeasels Twitch Integration plugin version 1.9.3 or earlier are affected. Any site that has the plugin enabled and allows contributor‑level users to edit pages with the data‑uuid attribute is vulnerable.
Risk and Exploitability
The CVSS score of 6.4 classifies the issue as moderate severity. The EPSS score of <1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation campaigns. Attackers must be authenticated with at least contributor privileges; they can then inject script via the plugin’s input fields, which is stored and later rendered to unsuspecting users.
OpenCVE Enrichment
EUVD