Impact
WordPress Simple Payment plugin, versions up to 2.5.4, contains a Cross Site Scripting flaw that allows attackers to inject malicious scripts into web pages because user‑supplied data is reflected without proper validation, permitting the injection of arbitrary JavaScript. The flaw can be exploited by embedding malicious scripts into plugin fields that are subsequently rendered in the user interface.
Affected Systems
The vulnerability affects the WordPress Simple Payment plugin developed by Ido Kobelkowsky, versions 2.5.4 and earlier. All installations of these vulnerable versions are at risk until the plugin is updated.
Risk and Exploitability
The EPSS score indicates a very low exploitation probability. The CVSS score of 6.5 is not listed in CISA KEV. Based on the description, the likely attack vector is client‑side injection; an attacker might target a site visitor by crafting a link or exploiting a form that the plugin processes. Successful exploitation would run malicious JavaScript in the victim's browser, enabling client‑side attacks. No hard prerequisites are required.
OpenCVE Enrichment