Impact
This vulnerability allows a Contributor user to inject arbitrary JavaScript into the WordPress site via the Podcast Importer SecondLine plugin, exposing the site to typical XSS attacks such as session hijacking or defacement. The flaw originates from insufficient input sanitization in the plugin’s handling of contributor input. An attacker who can craft a malicious payload would have the victim’s browser execute the injected script while visiting the site, potentially compromising user accounts and site integrity.
Affected Systems
The issue affects WordPress users running the Podcast Importer SecondLine plugin by SecondLine Themes, versions 1.5.6 and earlier. Any WordPress installation that has this plugin enabled and accepts contributor content is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not listed, so current exploitation probability is unknown, but the flaw is listed outside of the CISA KEV catalog. Because the vulnerability is limited to users with Contributor privileges, the attack vector requires legitimate access to the WordPress backend; however, once exploited, all visitors to the site can be impacted by the injected script.
OpenCVE Enrichment