Impact
Described as an unauthenticated cross‑site scripting (CWE‑79) flaw in WordPress Modula‑PRO plugin versions up to 2.10.8, allowing an attacker to inject malicious scripts that will execute in the browsers of any site visitor.
Affected Systems
Versions of the Modula‑PRO plugin from Chill Media Labs S.R.L. up to and including 2.10.8 are affected. WordPress sites that have not upgraded to at least versions 2.10.9 remain vulnerable.
Risk and Exploitability
CVSS v3.1 score of 7.1 indicates high severity. EPSS score of less than 1% shows a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The CVE explicitly states the flaw is unauthenticated, meaning no login is required for exploitation. While the description does not detail the attack vector, it is inferred that an attacker could target unauthenticated users through publicly accessible plugin interfaces to inject scripts. The high severity rating signals that impact on user confidentiality and integrity could arise if the injected script is used maliciously.
OpenCVE Enrichment