Impact
The CVE concerns an improper neutralization of user input in the WP Review Slider plugin, which permits the storage of malicious scripts that are subsequently rendered in the generated web page. Attackers who can submit data to the plugin could embed arbitrary script code that will execute in the browsers of any visitor who views the page, potentially compromising the normal operation of the site.
Affected Systems
The vulnerability affects all versions of the WP Review Slider plugin supplied by jgwhite33 that are equal to or earlier than version 13.9.
Risk and Exploitability
The base CVSS score is 6.5, indicating medium severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that large‑scale exploitation is not currently known. The attack vector is inferred to be remote via the web interface, as the stored XSS payload can be inserted through user‑facing input fields within the plugin.
OpenCVE Enrichment