Impact
The ReactPress – Create React App for WordPress plugin has a stored XSS flaw in which a legitimate user with subscriber‑level or higher access can insert arbitrary script code through the permalink field. The parameter is sanitized only by the sanitize_url() function, which fails to block remote URLs whose content contains script tags or event‑handler attributes. When that content is written verbatim to disk with file_put_contents(), the malicious script is persisted and executed whenever any user loads the affected page, enabling attackers to steal credentials, deface the site, or perform further attacks.
Affected Systems
All installations of rockiger:ReactPress – Create React App for WordPress up to and including version 3.4.0 are affected. Earlier versions are also vulnerable, as the code path that processes the permalink parameter has not changed in a way that mitigates the issue. The flaw is present only in the WP plugin context and requires the user to be authenticated with a role of Subscriber or higher.
Risk and Exploitability
The CVSS score of 6.4 classifies this issue as moderate severity. The EPSS score is not available, and the vulnerability is not yet listed in CISA’s KEV catalog. Attackers must first authenticate to WordPress and obtain a role of Subscriber or higher; once they do, they can inject malicious scripts that will be rendered in the browser of any user who visits the stolen link. Because the payload is stored on the server, it can impact a wide user base and the vulnerability can be exploited repeatedly without repeated privilege escalation. No publicly known exploits have been documented, but the mechanics of the flaw make it feasible for an attacker with access rights to deploy scripts that could lead to data theft or defacement.
OpenCVE Enrichment