CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. It affects WordPress, Java. Exploitation may require the attacker to be authenticated.
Original NVD Description
Stored XSS in the IMPress for IDX Broker WordPress plugin before 2.6.2 allows authenticated attackers with minimal (subscriber-level) permissions to save arbitrary JavaScript in the plugin's settings panel via the idx_update_recaptcha_key AJAX action and a crafted idx_recaptcha_site_key parameter, which would then be executed in the browser of any administrator visiting the panel. This could be used to create new administrator-level accounts.
Related CVEs
Other vulnerabilities affecting the same vendor(s)