Impact
Unauthenticated Cross Site Scripting exists in the WordPress WP Data Access plugin versions up to 5.5.79. The flaw allows an attacker to inject arbitrary client‑side code that is executed by any user who views affected pages, potentially leading to data theft, session hijacking, defacement, or the delivery of phishing content.
Affected Systems
The vulnerability impacts installations of the Passionate Programmer Peter WordPress WP Data Access plugin with a version of 5.5.79 or earlier. No specific sub‑versions are listed, so all releases in that range are considered at risk.
Risk and Exploitability
The flaw has a CVSS score of 7.1 and is publicly disclosed with no documented exploit. Because the vulnerability is unauthenticated and affects data that is rendered without proper escaping, any visitor to the site can be impacted. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, though its severity warrants prompt remediation.
OpenCVE Enrichment