Impact
The vulnerability allows stored cross‑site scripting through the Advanced Custom Fields: Font Awesome Field plugin. An attacker can inject malicious JavaScript that is persisted in the WordPress database and executed whenever any user views the affected content. This can lead to session hijacking, defacement, or further attacks against the site’s users and administrators.
Affected Systems
The issue exists in all releases of Justin Kruit’s Advanced Custom Fields: Font Awesome Field plugin up to version 5.0.2.
Risk and Exploitability
With a CVSS score of 6.5 the flaw represents a moderate‑severity risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet become widely exploited. Nonetheless, the stored XSS nature means that any authenticated or unauthenticated user who can view the affected content may be exposed to malicious scripts if the attacker successfully injects payloads via the plugin’s input fields.
OpenCVE Enrichment