Impact
The WowAddons plugin for WordPress, when installed at version 1.6.14 or earlier, contains an unauthenticated cross‑site scripting flaw. The CVE description does not explicitly state the root cause, but it is inferred that user‑supplied content accepted through the plugin’s interface is not properly sanitized, allowing an attacker to inject arbitrary JavaScript that executes in the browsers of any site visitor who views a page rendered by the plugin. Injected scripts can steal session cookies, deface content, redirect users to malicious sites, or otherwise compromise user trust and data integrity.
Affected Systems
All WordPress sites that have installed the WowAddons plugin at version 1.6.14 or lower are affected. The vulnerability is limited to the plugin; core WordPress and other plugins are not impacted.
Risk and Exploitability
The CVSS score of 7.1 reflects moderate‑to‑high severity, and no authentication is required for exploitation. The EPSS score of < 1 % indicates a very low current probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector involves any user who can submit data through the plugin’s input mechanisms, which are exposed to all site visitors. Once a malicious payload is delivered, it runs in the victim’s browser, providing the attacker with the same privileges as the site visitor.
OpenCVE Enrichment