Impact
Improper neutralization of input during web page generation allows malicious script code to be stored by the PSM Plugins SupportCandy plugin. When a user views the affected page, the injected script executes in the browser, enabling a range of defacement or manipulation of page content.
Affected Systems
The vulnerability affects all released versions of the PSM Plugins SupportCandy WordPress plugin up to and including version 3.4.8. Users running any of these versions are susceptible unless the plugin has been removed or otherwise mitigated.
Risk and Exploitability
The CVSS score of 6.5 signals moderate severity, while the EPSS score of less than 1% indicates that exploitation is currently considered rare. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply malicious input that is stored by the plugin and later rendered to a user’s browser; no higher privileges or additional conditions are documented in the CVE description.
OpenCVE Enrichment