Impact
A Cross Site Scripting vulnerability exists in the PublishPress Series WordPress plugin for versions 3.1.3 and earlier. The flaw allows a contributor user to inject arbitrary JavaScript or HTML into posts or series metadata. Because the input is rendered without proper escaping, an attacker can execute code in the context of any visitor to the site, enabling session hijacking, defacement, or redirection. The issue maps to CWE-79 and was scored with a CVSS base of 6.5 by the CNA.
Affected Systems
The affected product is PublishPress Series plugin for WordPress, with all releases through version 3.1.3. Site administrators should check the active plugin version and confirm whether it is below the fixed 3.1.4 threshold. The CNA has provided a single mitigation: upgrade to the latest version or later.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the lack of an EPSS value or KEV listing does not diminish the risk of exploitation in a widely deployed plugin. An attacker only needs the ability to submit content as a contributor or obtain a contributor account. If attackers can access the site with a contributor role, they can exploit the vulnerability to run scripts that affect all site users. Prompt patching is therefore recommended to eliminate the exposure.
OpenCVE Enrichment