Impact
The PublishPress Series plugin, version 2.17.0 and earlier, contains an improper neutralization of input during web page generation that allows a stored cross‑site scripting (XSS) payload to be persisted and executed on pages rendered by the plugin. An attacker who can create or edit series data could inject malicious JavaScript that will run in the browsers of any users who view the affected series content, potentially compromising user sessions, defacing the site, or delivering further attacks.
Affected Systems
Affected versions include the PublishPress Series WordPress plugin from its initial release through 2.17.0. Anyone using any of those releases, especially those that allow administrators or other privileged users to add or edit series entries, is at risk if the content is displayed on the front‑end.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate overall severity, and the EPSS score is not available, but the lack of a KEV listing suggests no known widespread exploitation. The vulnerability is typically exploitable when an attacker can inject input via a series entry that is later rendered in the browser. Consequently, the risk is moderate but significant for sites that rely on the affected plugin to display user‑generated content; timely patching is recommended.
OpenCVE Enrichment