Impact
This vulnerability is a stored cross‑site scripting flaw in the Articles Anywhere extension for Joomla. The extension accepts link options such as onclick and onmouseover, and in versions prior to 20.0.0 those options are turned into real HTML event attributes without validating the author’s trust level. Because the plugin syntax passes Joomla’s normal author content filter, the executable HTML is generated later, allowing an attacker who can create or edit content to embed malicious JavaScript that will run in the browsers of any site visitor. The weakness maps to the common web application flaw represented by CWE‑79.
Affected Systems
The flaw affects the Free and Pro variants of the Articles Anywhere extension published by regularlabs.com, when installed on Joomla sites running any major version lower than version 20.0.0. Sites that have not upgraded to the 20.0.0 release or later, and that use.
Risk and Exploitability
The CVSS base score of 7.5 indicates moderate‑to‑high impact, primarily on confidentiality, integrity, and availability through subverted user interactions. Because the flaw is injected through site authoring, the attack requires an attacker who can add or modify content, which is a privileged action but does not require external network access. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. However, if an attacker obtains content‑author privileges, the stored XSS payload will persist and can be executed on every page that renders the affected article, potentially leading to session hijacking, defacement, or credential theft for all site visitors.
OpenCVE Enrichment