Impact
The vulnerability allows authenticated users with at least Contributor rights to inject arbitrary JavaScript via the angle parameter. Once stored, the malicious script executes whenever a visitor loads the affected page. The flaw is caused by insufficient input sanitization and output escaping and is classified as CWE‑79.
Affected Systems
The issue affects the bnielsen Custom Word Cloud WordPress plugin in all releases up to and including version 0.3. Users deploying these versions are at risk when employing the plugin on any WordPress site.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of < 1 % reflects a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only authenticated access with Contributor‑level or higher roles; no external input is needed. Once injected, the payload remains until the plugin data is cleaned or the plugin is updated.
OpenCVE Enrichment
EUVD