Impact
A failure to enforce authorization on one of Topcontent’s request handlers allows an attacker without credentials to submit content that the plugin stores without sanitising HTML. The stored data is then rendered as part of a post, enabling the injection of malicious JavaScript into any page that displays the post. This stored XSS flaw can compromise user accounts, deface sites, and serve as a vector for further attacks on visitors. The weakness aligns with common scripting and authorization flaws.
Affected Systems
Any WordPress site that has installed the Topcontent plugin with a version of 1.2.1 or earlier and has not configured an API key is vulnerable. The plugin may appear on sites hosted by a variety of users, from personal blogs to corporate websites, because the flaw is in the public‑facing API endpoint of the plugin.
Risk and Exploitability
The vulnerability can be exploited unauthenticated, meaning any internet‑connected attacker can craft a payload and submit it to the vulnerable endpoint. With a CVSS score of 8.8 and an EPSS score of < 1%, the flaw still poses a high severity risk despite the low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, but the potential impact of widespread XSS warrants immediate attention.
OpenCVE Enrichment