Impact
An unauthenticated cross-site scripting flaw in the Tailored Tools WordPress plugin affects all versions up to 3.0.2, allowing the insertion of arbitrary JavaScript into pages served by the plugin. The lack of an authentication requirement means any user who can access the plugin's public interfaces can exploit the flaw. Based on the description, it is inferred that the vulnerability can be triggered by supplying malicious payloads through URLs or form submissions that the plugin processes without proper sanitization.
Affected Systems
Affected systems are WordPress installations that have the Tailored Media Tailored Tools plugin version 3.0.2 or earlier installed. No particular server configuration, theme, or WordPress core version is required for exploitation, so any site using the vulnerable plugin version is at risk.
Risk and Exploitability
CVSS score of 7.1 classifies this issue as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. The exploit probability remains uncertain, but the absence of any authentication barrier implies that an attacker can initiate the attack from outside the site by crafting a malicious request targeting the plugin’s endpoints. Though no confirmed attack patterns are reported, the combination of high severity and broad impact makes the flaw a tangible risk for WordPress sites deploying the plugin.
OpenCVE Enrichment