Impact
The vulnerability allows an authenticated user with subscriber‑level permissions to store arbitrary JavaScript in the 'first_name' field of a user profile. When an administrator later views that profile, the stored script runs in the administrator's browser session, enabling an attacker to execute scripts with the administrator's privileges. This is a stored cross‑site scripting flaw classified as CWE‑79 and can be used to hijack admin sessions, deface pages, or steal sensitive information that the administrator can see.
Affected Systems
WordPress plugin WP Crowdfunding, all versions up to and including 2.2.1. The flaw exists in every installation of the plugin in those releases and will persist until the plugin is upgraded or the data causing the injection is removed.
Risk and Exploitability
The CVSS score is 6.4 and no EPSS score is available. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires an authenticated account with at least subscriber privileges; the attacker can inject malicious JavaScript that will be executed whenever an administrator views the affected user's profile. The attack vector is authenticated code injection via the plugin’s user interface, representing a moderate to high risk for sites that use the affected plugin version.
OpenCVE Enrichment