Impact
The WowAddons plugin for WordPress, in versions 1.6.14 and earlier, contains an unauthenticated cross‑site scripting flaw that allows attackers to inject arbitrary JavaScript through publicly exposed input fields. The likely attack vector is a visitor who submits or otherwise causes the plugin to render malicious code; once a page including this code is viewed, the script executes in the attacker’s web browser with the same privileges as that visitor, potentially enabling cookie theft, session hijacking, defacement, or redirection. This weakness is a typical CWE‑79 vulnerability caused by improper input sanitization.
Affected Systems
All WordPress installations that have the WowAddons plugin version 1.6.14 or lower installed are affected. The WordPress core and other plugins are not directly impacted by this vulnerability.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity, and the EPSS score of < 1 % reflects a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. No authentication is required, and the likely attack vector is an unauthenticated user exploiting public input fields to trick site visitors into executing injected JavaScript.
OpenCVE Enrichment