Impact
The Smart SEO Tool WordPress plugin, versions 4.1.2 and earlier, contains a contributor Cross Site Scripting flaw that allows an attacker to insert arbitrary JavaScript payloads when submitting content through the plugin's web interface.
Affected Systems
The Smart SEO Tool WordPress plugin developed by wbolt.com, any release up to and including 4.1.2, is affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low proposed exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the plugin’s contributor submission interface, where a crafted input can introduce malicious JavaScript into rendered pages.
OpenCVE Enrichment