Impact
Contributor Cross Site Scripting has been identified in the WordPress Fluent Support plugin versions 2.3.0 and earlier. The flaw allows a user with contributor privileges to insert unsanitized scripts into the content managed by the plugin, which will then be executed in the browsers of visitors who view the affected page. This client‑side code execution can compromise the confidentiality and integrity of the site’s users by running arbitrary JavaScript in their context.
Affected Systems
All installations of the WPManageNinja Fluent Support plugin with a version of 2.3.0 or older on WordPress sites are vulnerable. The affected product is the Fluent Support plugin, version 2.3.0 or earlier.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate impact, while the EPSS score of less than 1 percent suggests a very low likelihood of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves a contributor account that can submit content; the exploiter would need a victim to visit a page that renders the injected script. No additional privileged access is required beyond the ability to add content.
OpenCVE Enrichment