Impact
The vulnerability arises from incomplete input sanitization and output escaping in the DoFollow Case by Case plugin. A malicious actor can insert arbitrary JavaScript into a comment, which is stored and rendered on the target post. When an administrator later approves the comment, the payload executes in the browsers of all users viewing the post, enabling theft of credentials, session hijacking, or defacement. This flaw is categorized as CWE‑79.
Affected Systems
Any WordPress site that has the DoFollow Case by Case plugin installed, version 3.6.0 or earlier. The plugin is supplied by the vendor apasionados and is available in the WordPress plugin repository. All versions up to and including 3.6.0 are affected; later releases are not listed as vulnerable.
Risk and Exploitability
With a CVSS score of 7.2 and no EPSS score available, the vulnerability represents a moderate‑to‑high risk. The exploit can be performed without authentication, simply by submitting a crafted comment to an affected post. Comment moderation can delay detection but does not block the payload. Although it is not currently listed in the CISA KEV catalog, the lack of a defensive patch means the risk remains high.
OpenCVE Enrichment