Impact
The SH Email Alert plugin for WordPress is vulnerable to Reflected Cross‑Site Scripting through the 'mid' query parameter. The plugin does not properly sanitize user input or escape output before rendering it, allowing unauthenticated users to inject arbitrary web scripts that execute when a victim visits a crafted URL.
Affected Systems
The vulnerability affects the SH Email Alert plugin distributed by samhoamt for WordPress. All released versions up to and including 1.0 are affected; later releases, if any, are not documented as impacted.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by persuading a user to click a specially crafted link that triggers the reflected scripting in the victim’s browser.
OpenCVE Enrichment
EUVD