Impact
The vulnerability occurs when the Patterns Kit WordPress plugin does not properly escape a link attribute before a client‑side script inserts it into a page. A user with the Contributor role can embed a malicious payload that is stored and then executed in the browser of any visitor who views the content and clicks the affected link. The stored script can run with the victim’s browser context, enabling attackers to steal sensitive data, deface the site, or perform other malicious actions. The impact is a persistence of malicious code that affects all users who access the compromised content.
Affected Systems
Any WordPress site that has the Patterns Kit plugin installed in a version 1.0.3 or earlier is affected. The vendor is listed as "Patterns Kit" and the product is the WordPress plugin. No specific sub‑versions are identified beyond the upper bound of 1.0.3.
Risk and Exploitability
Because this is a stored XSS vulnerability, the risk is high for sites that allow Contributors to add content. The EPSS score is not available, so the precise likelihood of exploitation is unknown, but the lack of escaping provides a straightforward attack path. There is no indication that this flaw has been exploited in the wild, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. Nonetheless, any attacker who can attain Contributor privileges can obtain persistence by injecting malicious JavaScript that will run whenever a user clicks the affected link.
OpenCVE Enrichment