Impact
A stored cross‑site scripting flaw allows attackers to inject arbitrary HTML or JavaScript into the output of the WordPress Presto Player plugin. The vulnerability arises from improper neutralization of user input during web page generation, enabling a malicious user to embed payloads that will execute in the browsers of visitors who view affected content. The stored nature of the flaw means the injected code persists until the content is removed or sanitized, potentially impacting confidentiality, integrity, and availability of the site and its visitors.
Affected Systems
The issue occurs in the Brainstorm Force Presto Player plugin for WordPress through version 4.5.2. Any WordPress installation that has this plugin installed and does not upgrade to version 4.5.3 or later is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers could exploit this issue by inserting malicious scripts through the plugin's content input fields, which are then rendered in browsers viewing the content. Because the flaw is stored, once injected, it will affect all users who load the affected content, making the risk significant for sites without mitigations.
OpenCVE Enrichment