Impact
The Parsi Date plugin for WordPress allows unauthenticated users to inject arbitrary JavaScript via vulnerable front‑end input handling, leading to a stored or reflected XSS instance. An attacker can embed malicious scripts that execute in a visitor’s browser, potentially stealing session cookies, phishing, or defacing the site. The vulnerability does not provide direct compromise of the server or data stealing from the backend, but it can undermine user trust and compromise client‑side confidentiality.
Affected Systems
All installations of the WordPress Parsi Date plugin version 6.3 or earlier, authored by Morteza Geransayeh, are affected. The vulnerability is specific to the plugin’s input handling paths and does not impact other WordPress core components or unrelated plugins.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity level. No EPSS value is supplied, so the precise likelihood of exploitation cannot be quantified, but the lack of authentication requirements and the presence of a typical user input sink means an attacker can exploit it from the public internet. The vulnerability is not currently listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. However, XSS risks are well understood, and site owners should treat it as a high‑priority fix.
OpenCVE Enrichment