Impact
The 评论小秘书 WordPress plugin contains a reflected XSS flaw in its settings page because the $_SERVER['PHP_SELF'] value is printed without proper encoding. This bug allows an attacker to embed malicious JavaScript in a URL or form input that is then reflected back to the browser. An unauthenticated user who views the affected page after following a crafted link may be able to execute arbitrary client‑side code, potentially hijacking sessions or defacing the site.
Affected Systems
All WordPress installations running the 评论小秘书 plugin up to and including version 1.3.2 are affected. The issue exists in every release prior to 1.3.3, if such a release exists. No specific server regions or configurations are listed, but any site publishing the plugin’s settings page could be vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 6.1, indicating moderate severity. The EPSS score of less than 1% shows that, while exploitation is possible, it is currently considered unlikely. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploits. Based on the description, the likely attack vector is a manipulated URL that causes the victim’s browser to execute attacker‑supplied script when they view the plugin page. Only a scenario where an exploitable URL is delivered to a user who then visits the page would lead to impact.
OpenCVE Enrichment