Impact
The vulnerability allows a contributor to inject arbitrary JavaScript into the Powerkit plugin’s output, leading to potential cookie theft, session hijacking, defacement, or execution of malicious code in the victim’s browser. The weakness is a classic cross‑site scripting flaw (CWE‑79) that can compromise the confidentiality and integrity of user data and the availability of the site for legitimate users.
Affected Systems
WordPress installations using the Powerkit plugin version 3.1.0 or earlier from codesupplyco. Users who have assigned the Contributor role or similar permissions that allow modification of plugin content are affected.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is considered moderate. No EPSS score is available, and it is not listed in CISA KEV, indicating a lower current exploitation probability. The likely attack vector is through a contributor account interacting with the plugin’s interface; this inference is drawn from the description of a Contributor‑based XSS. Exploitation requires authenticated access with content editing rights, but the injected script runs in the context of site visitors, enabling broader impact.
OpenCVE Enrichment