Impact
The vulnerability is a classic Cross Site Scripting flaw that allows any user to inject malicious scripts into the WordPress WPIDE – File Manager & Code Editor plugin. This flaw is identified as CWE‑79 and could be used by an attacker to deface the site, steal session cookies, or perform other browser‑based attacks. The vulnerability is unauthenticated, meaning it can be leveraged by anyone who can load the plugin interface.
Affected Systems
The affected product is XplodedThemes’ WPIDE – File Manager & Code Editor plugin for WordPress, with all releases up to and including version 3.5.7. Users running these versions are at risk, while versions 3.5.8 and later contain the fix.
Risk and Exploitability
The CVSS score of 7.1 classifies this issue as a high‑severity flaw. EPSS is not available, but the lack of a KEV listing suggests it is not yet commonly exploited. The attack vector is inferred to be any user who can load the plugin, implying that the vulnerability is exploitable without special permissions.
OpenCVE Enrichment