Impact
The WordPress plugin Post Status Notifier Lite before version 1.13.0 fails to properly escape the URL parameter named mod before reflecting it in the admin settings page. This weakness (CWE‑79) allows an attacker to inject arbitrary script that is executed in the context of a logged‑in administrator when that user opens a specially crafted link.
Affected Systems
WordPress plugin Post Status Notifier Lite, versions earlier than 1.13.0.
Risk and Exploitability
The vulnerability has a CVSS score of 4.8, indicating moderate severity, and an EPSS score of less than 1 %, suggesting a low likelihood of exploitation today. It is not listed in the CISA KEV catalog. The attack vector is inferred to be a crafted URL presented to an administrator; when the admin clicks the link, the reflected script runs in the admin session, allowing phishing‑style attacks or credential theft. No network‑level exploit is required and the impact is limited to the compromised admin account.
OpenCVE Enrichment