Impact
A stored cross‑site scripting flaw exists in the Station Pro plugin for WordPress, introduced through the ‘width' and ‘height' parameters. Because the plugin does not properly sanitize or escape these values, a malicious authenticated user with Contributor role or higher can inject JavaScript that will be stored and subsequently executed whenever a user accesses a page that contains the injected values. This leads to client‑side script execution in the context of the rendered page.
Affected Systems
The affected product is Station Pro – Advanced Audio Streaming & Player for WordPress, with all versions up to and including 2.4.2 susceptible to exploitation. The vulnerability is documented for the WordPress plugin hosted by the vendor marviorocha.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The exploit requires the attacker to hold a Contributor or higher authenticated WordPress account, which limits the threat to sites where such permissions are available to potentially malicious actors.
OpenCVE Enrichment
EUVD