Impact
The vulnerability permits an attacker to inject malicious scripts into the WordPress OAuth Server plugin’s output, enabling arbitrary JavaScript execution in users’ browsers. This can lead to session hijacking, defacement, or redirection to malicious sites and is classified as a classic XSS flaw (CWE-79). The description indicates a contributor could inject scripts into the plugin, suggesting that untrusted input is reflected without proper sanitization.
Affected Systems
WordPress sites running the OAuth Server plugin by Jayson T Cote, version 4.5.1 or earlier.
Risk and Exploitability
The CVSS score of 6.5 denotes a moderate severity. No EPSS score is available, so the exploitation likelihood is uncertain but not negligible. The vulnerability is not listed in CISA’s KEV inventory. An attacker can exploit the flaw by supplying crafted requests or modifying plugin content that is then rendered to visitors, potentially compromising confidentiality and integrity of user sessions.
OpenCVE Enrichment