Impact
The Logo Slider WP plugin records the "lgx_tooltip_position" field without proper sanitization or escaping, enabling an attacker who holds contributor‑level or higher WordPress permissions to embed arbitrary JavaScript code. When a page that displays plugin content is requested, the injected script executes in the victim's browser context, potentially allowing the attacker to manipulate the page or run additional code.
Affected Systems
Any WordPress installation that uses the Logichunt Logo Slider WP – Responsive Logo Carousel, Logo Gallery & Logo Showcase plugin version 5.5 or earlier is affected. The flaw exists in all releases up to and including 5.5 regardless of theme or other plugins.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, classifying it as moderate severity, while an EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, implying no known large‑scale exploitation. Because only contributor‑level access is required, many users may possess the necessary permissions, raising the practical risk for sites with moderate to high traffic.
OpenCVE Enrichment