Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw present in the WordPress Automatic plugin versions prior to 3.135.1. This weakness allows attackers to inject malicious scripts into pages, potentially leading to hijacked user sessions, data theft, or malicious redirects. The flaw is classified as CWE‑79, indicating improper input validation leading to reflected or stored XSS.
Affected Systems
Vendors: ValvePress, plugin name: Automatic. Affected product versions are all releases of the WordPress Automatic plugin below 3.135.1. Users running any version prior to 3.135.1 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 signifies a high severity impact. The EPSS score is not available, but the absence of a KEV listing suggests no current widespread exploitation. Attackers do not need authentication, so the risk depends on user interaction with potentially malicious content. Without filtering, a user visiting a crafted page could execute malicious code in their browser context.
OpenCVE Enrichment