Impact
This vulnerability is a contributor cross‑site scripting issue in the Virtue/Ascend/Pinnacle Toolkit plugin for WordPress versions 4.9.12.1 and earlier. It allows attack code to be injected by a contributor and executed in the browser of users who view content managed through the plugin, potentially enabling defacement, phishing, or other client‑side attacks.
Affected Systems
The affected product is Nexcess’ Virtue/Ascend/Pinnacle Toolkit plugin for WordPress. All releases up to and including version 4.9.12.1 are vulnerable. The vendor states that updating to version 4.9.12.2 or newer removes the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers would most likely exploit the flaw by inserting malicious content through a contributor account, implying that an attacker needs at least contributor access or a similar level of permission to inject the harmful script.
OpenCVE Enrichment