Impact
An unauthenticated Cross Site Scripting flaw exists in the Maspik – Spam blacklist plugin up to version 2.9.1. An attacker can inject arbitrary JavaScript into pages served by WordPress, enabling session hijacking, cookie theft, defacement, or other malicious client‑side attacks. This vulnerability conforms to CWE‑79.
Affected Systems
WordPress sites that run the Maspik – Spam blacklist plug‑in supplied by yonifre, with versions 2.9.1 or earlier. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium severity flaw, and because no authentication is required to exploit it, an attacker can launch the attack solely by sending crafted input to the plugin. EPSS data is unavailable, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be through user‑input fields or URL parameters processed by the plugin, allowing the injection of malicious scripts that run in victims’ browsers.
OpenCVE Enrichment