Impact
The vulnerability is an unauthenticated cross‑site scripting flaw in the WordPress Anti Spam and list cleaner – AcyChecker plugin for versions up to 1.8.1. The plugin processes user‑supplied data without proper escaping, enabling injection of arbitrary JavaScript. Based on the description, it is inferred that an attacker could embed malicious scripts that execute in the browsers of visitors when the affected pages are rendered, potentially compromising the confidentiality of sensitive information and the integrity of the site’s content.
Affected Systems
The issue affects the WordPress Anti Spam and list cleaner – AcyChecker plugin developed by the AcyMailing Newsletter Team. Versions 1.8.1 and earlier are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is below 1%, implying a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The flaw is unauthenticated; an attacker does not need credentials to exploit it. Based on the nature of XSS, the likely attack vector involves malicious input delivered through the plugin’s public interfaces, which is then rendered without adequate sanitization.
OpenCVE Enrichment