Impact
The Software Issue Manager plugin for WordPress contains a stored cross‑site scripting flaw in the noaccess_msg parameter. This vulnerability is identified as CWE‑79, Cross‑Site Scripting. Insufficient input sanitization and output escaping let an authenticated user with Contributor or higher privileges inject arbitrary JavaScript, which is then executed in the browsers of any user who views the affected page. This client‑side injection can compromise the privacy and integrity of users who interact with those pages.
Affected Systems
The vulnerability impacts the Software Issue Manager plugin (Project Management, Bug and Issue Tracking) released by emarket‑design. All releases up to and including version 5.0.1 contain the flaw.
Risk and Exploitability
The CVSS score is 6.4, marking the flaw as moderate severity, while the EPSS score is below 1 %, indicating a very low, yet non‑zero, probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, an attacker must be authenticated with Contributor or higher access to exploit the flaw, making the attack vector an authenticated XSS attack through the plugin’s user interface.
OpenCVE Enrichment
EUVD