Impact
ProductDyno’s WordPress plugin contains an improper neutralization of input during web page generation, allowing attackers to inject malicious script through reflected XSS. The flaw resides in how user‑supplied data is incorporated into the response, giving an attacker the ability to execute arbitrary JavaScript in the victim’s browser, which can lead to session hijacking, defacement, or the delivery of further malware. This vulnerability is characterized as CWE‑79.
Affected Systems
The affected product is ProductDyno’s WordPress plugin, version 1.0.24 and earlier. The impact applies to all installations that include any version from the initial release through and including 1.0.24.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level, yet the EPSS score of less than 1% shows a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Likely, an attacker would need to craft a URL or form containing malicious input and entice a user to visit or submit it, thereby triggering the reflected attack vector.
OpenCVE Enrichment
EUVD