Impact
The Simple Payment plugin for WordPress, versions 2.5.1 and earlier, has an unauthenticated Cross‑Site Scripting flaw that allows attackers to inject arbitrary JavaScript into page content. This vulnerability can be exploited to hijack user sessions, deface sites, or redirect users to malicious hosts, and is classified as CWE‑79.
Affected Systems
Any WordPress installation that has the Simple Payment plugin (developed by Ido Kobelkowsky) installed and running version 2.5.1 or older is affected. No further version filtering is available beyond the <= 2.5.1 boundary.
Risk and Exploitability
The CVSS score of 7.1 indicates a high potential impact when combined with the fact that the exploit is unauthenticated, meaning an attacker only needs to trick a user into visiting a maliciously crafted URL or page that triggers the plugin’s rendering logic. EPSS information is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting it may not yet be widely exploited. Attackers can achieve arbitrary code execution in the context of a victim’s browser session, affecting confidentiality, integrity, and availability of web content.
OpenCVE Enrichment