Impact
The CoolClock WordPress plugin versions before 4.3.8 do not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed. Because the malicious code is stored, all subsequent views of the content by any site visitor will execute the script.
Affected Systems
WordPress sites using the CoolClock plugin version 4.3.8 or older. All installations are vulnerable; newer releases are safe.
Risk and Exploitability
a CVSS score of 6.8, as any JavaScript can be executed in the context of users who view the polluted content. The exploit requires a contributor or higher account on the WordPress site, a privilege that is often available to many content editors. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. An attacker therefore must compromise the site or obtain a contributor account to place the payload, though the stored nature allows it to affect all users after the injection.
OpenCVE Enrichment