Impact
The vulnerability is an improper neutralization of input during web page generation, allowing attacker supplied content to be reflected as executable script within pages rendered by the LTL Freight Quotes – Worldwide Express Edition plugin. The flaw can result in the execution of arbitrary client‑side code in the context of any user who loads affected pages.
Affected Systems
All installations of the enituretechnology LTL Freight Quotes – Worldwide Express Edition plugin with a version up to and including 5.0.21 are affected. The vulnerability is present in all releases from the first version through 5.0.21.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity, while the EPSS score of less than 1% demonstrates a very low probability of exploitation in the wild. The plugin is not listed in the CISA KEV catalog. The likely attack vector is a crafted URL or form input that is echoed back in the page response; this inference is made from the reflected nature of the flaw, which is not explicitly detailed in the CVE description.
OpenCVE Enrichment
EUVD