Impact
The List Subpages plugin for WordPress lets users define a "title" attribute for subpages. Because this input is not sanitized, the flaw is a CWE-79 Stored Cross‑Site Scripting vulnerability. An authenticated user with Contributor or higher privileges can inject arbitrary JavaScript into that title field. The malicious script is stored in the database and executes in the browsers of any visitor who opens the affected subpage, potentially enabling session hijacking, data theft, or defacement.
Affected Systems
All versions of the List Subpages plugin published by weblineindia up to and including 1.0.6 are impacted. No information about later releases is available, so it is assumed that 1.0.7 and newer contain the fix. Users should verify the plugin version and apply an update if necessary.
Risk and Exploitability
The CVSS score of 6.4 classifies the flaw as moderate to high severity. Although the EPSS score is reported as <1%, suggesting a very low current exploitation likelihood, this does not rule out future attacks. The plugin is not listed in CISA’s KEV catalog, indicating no known public exploitation. The attack vector is inferred to be an authenticated subpage edit operation, requiring at least Contributor-level access. The impact is client‑side script execution on any viewer of the infected page.
OpenCVE Enrichment
EUVD