Impact
The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 fails to validate the contents of files uploaded through its file storage feature and serves them back with an attacker‑controlled content type. This allows an unauthenticated attacker to store a file containing malicious JavaScript that executes in the browser of any user who opens it. The flaw is a classic example of a stored cross‑site scripting vulnerability (CWE‑79) that can lead to unauthorized execution of arbitrary code in the context of the victim’s browser, resulting in potential theft of session cookies, defacement, or further credential compromise.
Affected Systems
Any installation of the Verge3D Publishing and E-Commerce WordPress plugin with a version earlier than 4.13.1 is affected. The vulnerability exists in the plugin’s file storage API and is independent of the host WordPress version or other plugins.
Risk and Exploitability
The flaw is exploitable by any user with access to the web interface that accepts file uploads, and does not require authentication. Because the malicious payload is stored and executed in victims’ browsers, the risk of exploitation is high. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Despite the lack of a published CVSS score, the attack vector and impact suggest a severity in the high‑to‑critical range.
OpenCVE Enrichment