Impact
WordPress TrustedSite plugin versions 1.2.5 and earlier contain an unauthenticated Cross Site Scripting vulnerability that allows an attacker to inject arbitrary script code into the website. When the vulnerable code processes user‑supplied data, the malicious script can be reflected back to the browser, possibly targeting logged‑in users to steal credentials, session cookies, or perform other malicious actions on behalf of the victim. The weakness is a classic reflected input‑validation flaw, identified as CWE‑79, and provides a direct path for compromising confidentiality, integrity, or availability of website content and user sessions.
Affected Systems
Any WordPress installation that has the TrustedSite plugin installed at version 1.2.5 or earlier is affected. The product is named TrustedSite by TrustedSite and the vulnerability applies to all installations regardless of how the plugin is used, as the flaw does not require administrative privileges.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating a high‑severity threat. The EPSS score is not provided, so the current likelihood of exploitation is uncertain. The bug is not listed in the CISA KEV catalog, suggesting there is no confirmed widespread exploitation yet. However, because the flaw can be exploited by an unauthenticated attacker through normal web requests, the attack vector is likely remote via the web. Attackers could target unsuspecting visitors or users with logged sessions to deliver malicious payloads, leading to credential theft, defacement, or further compromise of the site.
OpenCVE Enrichment