Impact
The vulnerability allows unauthenticated attackers to store malicious JavaScript in comment content that is later executed when a page is rendered. The stored XSS can hijack user sessions, deface content, or redirect visitors. It is rated high severity with a CVSS score of 7.2, indicating significant impact if exploited.
Affected Systems
The issue affects the GSpeech TTS WordPress plugin in all releases up to and including version 3.22.0. Any WordPress installation that has this plugin and accepts comments is susceptible; the vulnerability is confined to the plugin’s rendering context and does not extend to core WordPress.
Risk and Exploitability
Attackers can submit the exploit payload without needing authentication by posting a specially crafted comment. The injected content is stored and later rewritten by the plugin’s output‑buffer callback, enabling script execution. The exploit is not listed in the CISA KEV catalog and the EPSS score is unavailable, but the high CVSS score signals a serious risk that could be leveraged if discovered.
OpenCVE Enrichment