Impact
The Virtue/Ascend/Pinnacle Toolkit plugin contains an unsanitized input field that lets a contributor submit JavaScript code, which is then rendered on the front‑end for all visitors. A successful exploit can be used to steal session cookies, deface content, or deliver additional malware, compromising user confidentiality and site integrity. The flaw does not allow direct remote code execution on the server, but it creates a powerful vector for social engineering and credential theft.
Affected Systems
WordPress installations that include the Nexcess Virtue/Ascend/Pinnacle Toolkit plugin version 4.9.12 or older. Any site using this component is susceptible, regardless of the number of contributors or the size of the audience.
Risk and Exploitability
With a CVSS base score of 6.5 the vulnerability is classified as moderate to high severity. The EPSS probability is below 1%, indicating few publicly documented attacks, and it is not listed in the CISA KEV catalog. The likely attack path is a contributor logging into the WordPress admin area and inserting malicious payloads through the plugin’s input controls; no elevated privileges or special network access are required.
OpenCVE Enrichment