Impact
This vulnerability permits an attacker to inject malicious JavaScript into the page that OTWthemes Widgetize Pages Light generates, because the plugin does not neutralize input before rendering it. The reflected XSS can lead to execution of arbitrary client‑side code in a victim’s browser, potentially enabling cookie theft, session hijacking, defacement, or phishing attacks. The issue is present in all releases of the plugin through version 3.0.
Affected Systems
Any WordPress site that has installed OTWthemes Widgetize Pages Light plugin, regardless of version, up to and including 3.0, is vulnerable. Sites that rely on this plugin to display user‑supplied content are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates significant impact. The EPSS score of less than 1% suggests a low overall exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. However, the attack vector is likely a crafted URL or form input that the plugin reflects verbatim, allowing an attacker to embed script when a page loads for a victim who submits or visits the crafted request.
OpenCVE Enrichment
EUVD