Impact
The Certifica WP plugin for WordPress is vulnerable to Stored Cross‑Site Scripting via the ‘evento’ parameter due to insufficient input sanitization and output escaping. Authenticated attackers with Contributor-level access and higher can inject arbitrary scripts that execute whenever a user views the injected event page, enabling malicious actions such as defacement or credential theft.
Affected Systems
WordPress plugin Certifica WP, provided by Moreira Pontocom. All releases through version 3.1 inclusive are affected. Users of older versions are safe.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score is under 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low probability of widespread exploitation. However, the attack requires authenticated Contributor‑level access, so an attacker must first acquire such a role or compromise an authorized account. Once the vulnerable ‘evento’ parameter is abused, the injected payload runs in the browser context of any visitor to the affected event page, potentially allowing cookie theft, session hijacking or site defacement.
OpenCVE Enrichment
EUVD