Impact
Subscriber Cross Site Scripting is a vulnerability that allows an attacker to inject malicious JavaScript into the PixelYourSite plugin, potentially enabling session hijacking, credential theft, or defacement of website content when users view a page that includes the exploited input. The flaw arises from unsanitized user input rendered in a browser context, which, once executed, can interact with the victim’s browser and the WordPress site. In the worst case, a malicious script could exfiltrate cookies, request sensitive data, or facilitate drive‑by attacks on visitors and administrators alike.
Affected Systems
The issue affects all installations of the PixelYourSite – Your smart PIXEL (TAG) Manager WordPress plugin version 11.4.1 or older. Users running these versions must review their plugin configuration and installed files for legacy code.
Risk and Exploitability
With a moderate CVSS score of 6.5 and no EPSS data available, the vulnerability carries a reasonable likelihood of exploitation in environments where the plugin is exposed to unauthenticated users. The absence of an entry in the CISA KEV list indicates no public exploits are known as of this assessment, but the XSS flaw can be triggered via crafted URLs or form submissions that inject code into the plugin’s output. The likely attack vector is remote, originating from an attacker who can persuade or trick a user into visiting a malicious URL or submitting forged data to the plugin’s input fields. Admin users or developers with editing rights could unintentionally introduce this payload during normal operations.
OpenCVE Enrichment