Impact
The Print, PDF, Email by PrintFriendly WordPress plugin contains a stored cross‑site scripting flaw in the ‘content sanitization and escaping allows an administrator‑level user to embed arbitrary JavaScript, which the plugin later outputs as part of a page. This lets the attacker run code in all visitors’ browsers, potentially stealing session cookies, injecting phishing content, or delivering further malicious payloads. The weakness is a classic input‑validation issue, identified as CWE‑79.
Affected Systems
Any WordPress site that has the Print, PDF, Email by PrintFriendly also contain the same code. Site owners should verify the installed plugin version and update to the latest release available from the vendor.
Risk and Exploitability
With a CVSS base score of 4.4 the vulnerability is classified as moderate severity, while the EPSS score of less than 1 % indicates a very low probability of exploitation in the wild and the issue is not listed in CISA’s KEV catalog. The flaw requires prior administrator‑level access; once the malicious script is stored it runs for all front‑end users, enabling attackers to compromise user confidentiality and integrity. Although the likelihood of exploitation is low, the potential damage from widespread client‑side code execution warrants prompt mitigation.
OpenCVE Enrichment