Impact
The Codemenschen Gift Vouchers plugin stores user-supplied data without proper neutralization, allowing attackers to inject malicious scripts that are later rendered on voucher pages. When a user views the impacted content, arbitrary JavaScript can be executed in the victim’s browser. This flaw does not provide direct remote code execution on the server side, but it can lead to client‑side compromise. Based on the description, it is inferred that such execution could be used for phishing or defacement, though these outcomes are not explicitly stated in the source.
Affected Systems
The Codemenschen Gift Vouchers WordPress plugin is vulnerable for all releases up to and including version 4.7.0. WordPress sites that have any of those versions installed are affected. The plugin is managed by Codemenschen.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity for this vulnerability. Its EPSS score of less than 1% suggests that exploitation is expected to be relatively rare. The flaw is a stored XSS that can be exploited remotely by submitting malicious content to the voucher system, making the attack vector remote. The vulnerability is not listed in the CISA KEV catalog. Because the flaw stores malicious scripts, even a single malicious input could affect many visitors who view the stored voucher content, presenting a serious risk for sites with active voucher usage.
OpenCVE Enrichment