Impact
The Author Box WP Lens plugin (by Netrr) suffers from a stored cross‑site scripting flaw due to improper input neutralization. It is inferred that the attacker can inject malicious JavaScript into an author box field, which the plugin stores without sanitization and later renders in the page. This permits the execution of arbitrary scripts in the browsers of any visitor, potentially cookie theft, defacement, or malicious redirects. The weakness is identified as CWE‑79.
Affected Systems
WordPress sites running Netrr’s Author Box WP Lens plugin version 2.1.5 or earlier are vulnerable. The issue applies across all releases from the initial release up to and including 2.1.5. Site administrators should verify the plugin version and upgrade or disable the plugin accordingly.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of active exploitation. It is inferred that the attack vector is purely web‑based, requiring only that an authenticated user input malicious code into the plugin’s author box interface. Because the code is stored and served to all visitors, exploitation does not require elevated privileges after the initial injection but can impact all users of the site. It is also inferred that the plugin’s widespread use on WordPress sites increases the potential impact. Currently, the vulnerability is not listed in CISA’s KEV catalog, so there is no known large‑scale exploitation, but the potential for misuse remains high.
OpenCVE Enrichment