Impact
Subscriber Cross Site Scripting (XSS) is present in WishList Member X plugin versions up to and including 3.32.0. The weakness, identified as CWE-79, arises from insufficient validation of user input in subscriber data fields, permitting an attacker to inject and execute arbitrary JavaScript in the context of a victim’s browser. This can lead to session hijacking, credential theft or defacement of the site, depending on the attacker’s goals and the user roles involved. The CVSS score of 6.5 reflects a moderate severity, indicating that successful exploitation requires the attacker to target a subscriber account or craft malicious input that is stored and rendered back to the user.
Affected Systems
The vulnerability affects the WishList Member X WordPress plugin, provided by Membership Software, in all releases through version 3.32.0. The specific product name is WishList Member X plugin, and any installation running a version equal to or older than 3.32.0 is potentially exposed.
Risk and Exploitability
The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a web-based action on the plugin’s subscriber data entry or management pages, where an attacker could supply malicious payloads that are subsequently displayed to other users. Successful exploitation would depend on the user’s role permissions and the extent of the plugin’s input handling. Because the issue is a typical reflected or stored XSS, an attacker with basic HTML knowledge can gain the ability to execute scripts in the victim’s browser, jeopardizing confidentiality, integrity and availability of the affected site’s user session data.
OpenCVE Enrichment