Impact
The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress contains a stored XSS flaw. Key detail from vendor description: "The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross‑Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping." An attacker with administrator‑level permissions can inject arbitrary web scripts into plugin settings that will execute whenever a user accesses an injected page. This allows session hijacking, credential theft, or defacement of reports and dashboard pages.
Affected Systems
Creative Minds Solutions; All installations of the CM Custom Reports plugin up to and including version 1.2.7 are affected. The vulnerability exists only on multi‑site WordPress installations where the unfiltered_html capability is disabled, and requires that an authenticated administrator has access to the plugin’s admin settings.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated administrator‑level access and insertion of malicious code via the plugin’s label field. The attack vector is internal to the site but can impact all users who view reports, potentially compromising confidentiality, integrity, and availability of user sessions.
OpenCVE Enrichment