Impact
The CC Child Pages plugin for WordPress is vulnerable to stored XSS due to the 'more' parameter being insufficiently sanitized and escaped. An attacker who has Contributor‑level permissions or higher can insert arbitrary JavaScript into a page. When any user views that page, the script executes in their browser, enabling credential theft, session hijacking, defacement or other client‑side attacks. The weakness is classified as CWE‑79.
Affected Systems
Vendor Caterham Computing offers the CC Child Pages plugin for WordPress. All versions up to and including 2.1.1 are affected. Versions 2.1.2 and newer contain the fix.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. Exploitation requires authenticated access with Contributor or higher privileges, which limits the threat to users who can edit or create pages. Because the attacker needs only to submit a crafted payload via the plugin’s editor, a successful exploit is straightforward once the access level is achieved. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread public exploitation yet.
OpenCVE Enrichment