Impact
The vulnerability is a Contributor Cross‑Site Scripting flaw in the Featured Video Plus WordPress plugin. It allows a user with contributor privileges to inject malicious scripts into the plugin’s content area, which are subsequently served to site visitors. This can lead to the theft of session cookies, credential phishing, or other client‑side attacks, compromising the confidentiality and integrity of site users.
Affected Systems
WordPress sites that use the Alex:Featured Video Plus plugin version 2.3.3 or earlier are affected. The plugin is a media‑content extension that developers and site administrators should keep at the latest release.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a moderate likelihood of exploitation in the wild. The failure condition is that an attacker must have contributor access to the site; once that exists, the attacker can craft a payload that activates when other visitors view the site. The client‑side nature of this flaw means that the impact is limited to users interacting with the compromised content, but the damage can be widespread in heavily trafficked sites.
OpenCVE Enrichment