Impact
The vulnerability is an unauthenticated cross‑site scripting flaw in the Facebook for WordPress plugin version 5.2.1 and earlier. The flaw resides in unsanitized input handling, enabling attackers to inject arbitrary JavaScript that executes in the context of any site visitor. This can lead to theft of user cookies, session hijacking, defacement, or the delivery of additional malicious payloads. The identified weakness is CWE‑79, reflecting failure to validate or encode user input.
Affected Systems
The affected product is Facebook’s "Facebook for WordPress" plugin installed in WordPress sites. Versions 5.2.1 and earlier are vulnerable. Any site running these versions of the plugin with the default configuration is affected, regardless of user role or authentication status.
Risk and Exploitability
The CVSS v3 score of 7.1 indicates a significant risk. The EPSS metric is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is exploitable without authentication, the attack vector is likely to be the Web; an attacker can target any visitor who accesses the site, possibly delivering malicious scripts via the plugin’s input fields or URL parameters. The impact is client‑side malware injection, with potential for credential compromise, account takeover, or defacement, and the overall risk is moderate to high especially for sites that rely heavily on the plugin for social integration.
OpenCVE Enrichment