Impact
The vulnerability the Gutenverse News WordPress plugin. Because the plugin applies a sanitisation contexts, unauthenticated users can embed JavaScript in comment content that will be executed when an administrator views the comment queue or when any visitor sees the approved post. This allows arbitrary script execution in the browser of those usersSS score is 8.8, and EPSS value is not available; the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw from any IP that can submit an unauthenticated comment, a capability normally available to anonymous visitors. The impact is limited to the browsers of administrators reviewing comments or visitors viewing approved content; the flaw remains until the malicious comments are removed or the plugin is updated.
Affected Systems
Any WordPress site that has the Gutenverse News plugin installed with a version earlier than 3.3.3 is affected. The vulnerability exists regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. Because the flaw is triggered by submitting a malformed comment without authentication, the attack vector is local to the web application and does not require privileged access; any external user can exploit it. The lack of EPSS data and the absence from the CISA KEV catalog suggest that no widespread exploitation has been publicly reported yet, but the available evidence shows that an attacker could inject and execute arbitrary JavaScript in the browsers of site administrators reviewing the comment queue or of visitors viewing content after the comment is approved.
OpenCVE Enrichment