Impact
The SOGO Add Script to Individual Pages Header Footer WordPress plugin, in versions 3.9 and earlier, fails to sanitize or escape custom header/footer script values entered through its post metabox. It also does not restrict the input to users with the unfiltered_html capability. Contributors and higher roles can therefore store arbitrary JavaScript that will execute in the browsers of administrators reviewing the post and of any visitor once the post is published. This Stored Cross‑Site Scripting flaw allows attackers to execute client‑side code with the privileges of the victim user, enabling session hijacking, credential theft, or malicious page defacement.
Affected Systems
This vulnerability affects the SOGO Add Script to Individual Pages Header Footer plugin for WordPress, version 3.9 or earlier. It applies to any WordPress site that has the plugin installed and has users with contributor or higher roles enabled to use the custom script functionality. The vendor for the plugin is not listed; the plugin is freely available in the WordPress plugin repository.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The plugin’s web interface is the primary attack vector; an attacker who can assume a contributor role or higher can submit the malicious script through the post edit screen. An administrator who views the post will run the script, and any site visitor will be exposed when the post is published. Because the flaw is stored and triggers in normal page rendering, it can be exploited without additional network‑based attacks. The lack of an EPSS score means the estimated exploitation probability is unknown, but the presence of the flaw in a publicly available plugin suggests potential for widespread impact.
OpenCVE Enrichment