Impact
An unauthenticated Cross Site Scripting flaw exists in Qode Music plugin versions 2.1.8.2 or earlier. The flaw allows an attacker to insert malicious JavaScript that will execute in the browsers of any visitor who loads a page rendered by the affected plugin. This can permit the attacker to manipulate page content, place hidden data on the page, or perform client‑side attacks on site users.
Affected Systems
WordPress sites that have the Qode Music plugin version 2.1.8.2 or earlier. The plugin is distributed by the vendor QODE and is commonly used to display music content within WordPress themes.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as moderate‑to‑high severity. The EPSS score is not provided and the issue is not listed in CISA’s KEV catalog, so it is unclear how often it is actively exploited. Nonetheless, the flaw is completely unauthenticated; any user able to view the vulnerable page can craft a payload that will run in the browsers of other visitors.
OpenCVE Enrichment