Impact
The Powerkit plugin for WordPress incorporates a regex‑based HTML attribute parser within its Lazy Load image processing routine. This flawed parsing allows an authenticated user with Contributor‑level access or higher to embed arbitrary JavaScript into stored content. When an affected page is viewed by any site visitor, the injected script executes in the visitor’s browser, enabling session hijacking, cookie theft, defacement, or other client‑side attacks.
Affected Systems
All installations of the Powerkit WordPress plugin provided by codesupplyco, from its initial release through version 3.0.4, are vulnerable. Any WordPress site that has installed or activated a vulnerable version of Powerkit is at risk, regardless of the underlying WordPress core version. No other vendors, products, or later plugin versions are affected.
Risk and Exploitability
The vulnerability carries a CVSS base score of 6.4, indicating moderate severity. Exploitation requires authenticated access at the Contributor level or higher, a privilege often granted to trusted collaborators. The flaw is stored, meaning the malicious payload persists in published content and will be delivered to all subsequent visitors who load the affected pages. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet; nevertheless, the potential impact warrants prompt remediation.
OpenCVE Enrichment