Impact
This vulnerability is a stored cross‑site scripting flaw in the VK All in One Expansion Unit WordPress plugin. An attacker who can authenticate to the site with contributor‑level or higher privileges can save malicious JavaScript within the 'vkExUnit_cta_img_position' post meta field. Because the plugin’s sanitization routine does not strip double‑quotes or event‑handler attributes and the output filter only rewrites disallowed iframe tags, the payload survives rendering and runs in the context of any user who views the affected page.
Affected Systems
The flaw affects the kurudrive VK All in One Expansion Unit plugin versions up to and including 9.118.0. All WordPress sites that have this plugin installed on those releases are vulnerable. If a site uses a version later than 9.118.0, the issue is presumed fixed, although site administrators should verify that the patch is applied.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of <1 % indicates a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability requires an authenticated attacker with contributor or higher privileges, a level of access that is common for content creators. Therefore, many sites that have this plugin and such user roles remain exposed until the plugin is updated or mitigated.
OpenCVE Enrichment