Impact
Subscriber Cross Site Scripting (XSS) is possible in Kalles Addons plugin versions 1.0.6 and earlier. The vulnerability allows an attacker to inject malicious scripts through subscriber data that is rendered in the plugin’s output, potentially enabling cookie theft, session hijacking, defacement, or malicious redirects. It represents a classic input validation flaw identified as CWE‑79.
Affected Systems
The4’s Kalles Addons WordPress plugin, any installation with version 1.0.6 or older, is affected. The flaw applies to all sites that use the plugin without applying the latest patch.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting the known exploitation rate is uncertain. The likely attack vector is through the subscription interface or subscriber listing pages where malicious payloads could be injected via user input. Although the vulnerability does not provide remote code execution, it can lead to significant phishing or credential compromise if the site has a large user base.
OpenCVE Enrichment