Impact
The Pinterest Site Verification plugin for WordPress contains a stored cross‑site scripting flaw caused by inadequate sanitization of the 'post_var' parameter in versions up to 1.8. Authenticated users with subscriber‑level rights may inject arbitrary JavaScript into the plugin’s settings, which is then rendered in web pages and executed by anyone who views an affected page. This vulnerability allows an attacker to execute arbitrary code in the context of site visitors, potentially exposing sensitive data, hijacking sessions, or defacing the site.
Affected Systems
WordPress sites that use the Pinterest Site Verification plugin (Meta Tag version 1.8 or earlier). The issue is confined to the plugin’s code and does not affect core WordPress or other plugins.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity, and the attack requires the attacker to have a subscriber‑level account on the target site. While the vulnerability is not exploitable by unauthenticated users, the potential impact of XSS is significant because it allows script execution across the site. No EPSS score or KEV listing is available, but the condition for exploitation is clear: an authenticated subscriber+ user must modify the plugin’s settings.
OpenCVE Enrichment