Impact
The Magic Edge – Lite WordPress plugin contains a stored XSS flaw that can be exploited through the height parameter in all releases up to 1.1.6. Because the input is not sanitized and the value is output without proper escaping, an attacker with Contributor or higher can embed JavaScript payloads into a page. When another user opens that page the malicious script runs in the victim’s browser, enabling defacement, credential theft, or session hijacking.
Affected Systems
WordPress installations that have the Magic Edge – Lite plugin installed in any version up to and including 1.1.6 are affected. The vulnerability is present in the plugin code that handles the height field; therefore any site using the plugin, regardless of its WordPress version, is at risk. The issue is specifically tied to the plugin provided by awssoft.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, which is considered moderate. Its EPSS score is below 1%, indicating that it is an unlikely target for widespread exploitation. The attack requires authenticated access with at least Contributor privileges, so it cannot be triggered by a guest user. Although the vulnerability is not listed in the CISA KEV catalog, it should still be addressed promptly because once a contributor injects a script, any subsequent visitor to the affected page will be exposed. The design of the plugin makes the exploitation path straightforward for an attacker who has valid credentials on the WordPress site.
OpenCVE Enrichment
EUVD