Impact
A Cross Site Scripting (XSS) vulnerability exists in the WordPress Machete plugin version 5.2 and earlier. The plugin does not properly sanitize or encode user input, allowing malicious JavaScript to be injected. This weakness is identified as CWE‑79.
Affected Systems
WordPress sites that have the Machete plugin installed in a version older than 5.3 are vulnerable. The affected product is the Machete plugin from Nilo Velez. No other WordPress components are explicitly cited as affected. Site administrators should verify the installed plugin version and upgrade if possible.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of less than 1% suggests exploitation is very unlikely at present. The vulnerability is not reported in the CISA KEV catalog. Based on the description, it is inferred that an attacker could exploit a user‑controlled input that the plugin fails to escape, enabling injection of JavaScript that would execute in the browsers of visitors who view affected pages. No public proof of exploitation is documented, but the presence of the flaw could allow malicious scripts to run on the front‑end.
OpenCVE Enrichment