Impact
An unauthenticated Cross Site Scripting (XSS) vulnerability exists in the WordPress Autopay plugin up to version 5.0.0. The flaw permits injection of arbitrary JavaScript into the plugin’s output. Based on the description, it is inferred that an attacker could manipulate the content shown to site visitors, potentially enabling session hijacking, defacement, or malicious redirects, but these specific outcomes are not explicitly stated in the CVE text.
Affected Systems
The vulnerability affects the WordPress Autopay plugin, versions 5.0.0 and earlier. Any site that has installed a version prior to 5.0.1 is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity, and exploitation does not require authentication or privilege escalation. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of widespread exploitation is uncertain. However, the unauthenticated nature implies that any visitor to a site using the vulnerable plugin could trigger the malicious script.
OpenCVE Enrichment