Impact
The EONSR AEO Agent WordPress plugin up to version 3.7.9 does not enforce an authorization check on a REST API route and deliberately turns off HTML sanitization when saving posts. This flaw allows unauthenticated attackers to create posts that are attributed to an administrator and contain arbitrary client‑side scripts. When any visitor, including administrators, views the post, the malicious script executes in their browser, creating a stored cross‑site scripting vulnerability.
Affected Systems
WordPress sites that have the EONSR AEO Agent plugin version 3.7.9 or earlier installed.
Risk and Exploitability
The vulnerability can be exploited remotely by sending a crafted POST request to the susceptible REST API endpoint without authentication. The EPSS score is less than 1 % and the issue is not listed in CISA’s KEV catalog, while the CVSS score of 6.1 indicates moderate severity. Because the flaw allows arbitrary scripts to persist in published content that every site visitor can load, the potential impact is high—non‑authenticated users can provide content that will execute in the context of any visitor’s browser, enabling session hijacking, defacement, and data exfiltration.
OpenCVE Enrichment