Impact
Category Dropdown List is a WordPress plugin that can reflect arbitrary user‑supplied input via the $_SERVER['PHP_SELF'] variable. The plugin does not sanitize or escape the value before output, allowing unauthenticated attackers to inject malicious JavaScript into the web page. If a user follows a crafted link, the injected script can run in the victim's browser, potentially stealing session cookies, defacing the site, or performing further malicious actions.
Affected Systems
The vulnerability affects the Category Dropdown List plugin for WordPress supplied by the contributor pandikamal03. All releases up to and including version 1.0 are vulnerable. Users running the plugin on their WordPress sites with these versions are exposed to the risk.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score is less than 1%, suggesting a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, and exploitation requires only that an unauthenticated user be tricked into clicking a malicious URL; no authentication or administrative privileges are needed. The risk to the host and its visitors is therefore moderate, but with a low likelihood of real‑world exploitation at present.
OpenCVE Enrichment