Impact
An unauthenticated attacker can store malicious JavaScript in the settings of KeyWord Collector by submitting data through the settings page. This stored payload is then served to administrators when they open the settings interface and to any visitor who loads a page that displays the plugin’s output. The flaw arises from a lack of authorisation checks and the absence of proper escaping, which allows arbitrary code execution in the context of the rendered page. When executed, the script can read cookies, hijack sessions, modify page content, or carry out other malicious activities.
Affected Systems
All versions of the WordPress plugin KeyWord Collector up to and including 1.4 are affected. The vendor list identifies the product simply as "KeyWord Collector" with no further version detail, indicating the vulnerability spans the entire release set through 1.4. WordPress sites that have this plugin installed, regardless of other configurations, are at risk.
Risk and Exploitability
The vulnerability is a high‑severity stored XSS that does not require prior authentication, meaning an attacker can deliver the malicious payload without logging in. The EPSS score is unavailable, so the likelihood of exploitation is uncertain; however, the absence of a CISA KEV designation suggests it has not yet been confirmed in the wild. Because the flaw allows arbitrary script execution on administrator or visitor pages, the potential impact is escalation of privilege and defacement, making the risk level significant.
OpenCVE Enrichment