Impact
The vulnerability allows a malicious actor with subscriber-level or higher access on a WordPress site to inject arbitrary JavaScript through the 'data' parameter of the plugin’s REST endpoint. Because the input is not sanitized and the output is not escaped when stored, the injected script later runs in the browser of any user who views the affected page, potentially letting attackers steal session cookies, hijack accounts, or perform defacement.
Affected Systems
WordPress sites using the Email Marketing for WordPress and WooCommerce – Retainful plugin, version 1.0.10 or earlier.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate risk, and the attack requires authenticated access with subscriber-level or higher privileges. While broad exploitation is limited to sites that have the legacy plugin, the attack is straightforward once authorized, and no EPSS data is available. The vulnerability is not listed in CISA KEV, but its client‑side effect means that any compromised site can expose users to cross‑site scripting risks.
OpenCVE Enrichment