Impact
Unauthenticated Cross Site Scripting (XSS) is present in WPCS versions up to 1.3.2. The flaw allows an attacker to inject arbitrary client‑side script into web pages served by WordPress sites that host the affected plugin. The injected code can run in the context of the victim’s browser, enabling cookie theft, session hijacking, defacement, and delivery of additional malware. The vulnerability is a classic input‑validation weakness (CWE-79).
Affected Systems
RealMag777’s WPCS WordPress plugin for sites that have installed any version of the software up through 1.3.2 is affected. Sites using earlier versions or the updated 1.3.3 and later are safe from this specific flaw.
Risk and Exploitability
The Common Vulnerability Scoring System gives this flaw a 7.1 score, indicating a medium‑to‑high severity. The Exploit Prediction Scoring System (EPSS) is not available, so the current exploit probability is not quantified. This entry is not listed in CISA’s Known Exploited Vulnerabilities catalog, but the unauthenticated nature of the flaw means that any visitor to a vulnerable site could potentially trigger the vulnerability. Attackers would typically craft a malicious URL or input that is echoed by the plugin without proper encoding, then lure a target user to the page to execute the injected script. Because the vulnerability is cross‑site, it can affect all users who load the affected page.
OpenCVE Enrichment