Impact
The flaw allows users with contributor permissions or higher to embed malicious JavaScript into post metadata that is rendered without proper sanitization. When an administrator or editor views the content, the injected script executes in their browser, enabling session hijacking, redirection, data theft, or content manipulation. The attack can compromise the confidentiality, integrity, and availability of the site from the victim’s browser context.
Affected Systems
This flaw affects the WordPress plugin Saitama Addon Pack through version 1.0.8. Any installation of the plugin up to and including 1.0.8 is susceptible, regardless of the site’s overall WordPress version or theme. The plugin’s developer is not specified beyond the generic vendor name, and no additional version details are provided in the CNA data.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation yet. The CVSS score is not provided in the data. The flaw allows any user with contributor role or higher to inject and store JavaScript in post metadata that is rendered unescaped when viewed by higher‑privileged users, potentially compromising the victim’s browser session, redirecting them, stealing data, or modifying content. The attack vector is authenticated use of the plugin’s post metadata interface.
OpenCVE Enrichment