Impact
The vulnerability is an improper neutralization of input that permits reflected cross‑site scripting. This means an attacker can embed malicious script fragments that are returned to users when they view affected pages. The result is arbitrary JavaScript execution in the victim’s browser context, potentially exposing user credentials or enabling other client‑side attacks.
Affected Systems
WordPress sites that have installed the 5centsCDN plugin version 25.4.15 or earlier are vulnerable. The issue applies to all installations of the plugin from the earliest available version up to and including 25.4.15.
Risk and Exploitability
The CVSS score of 7.1 categorizes the flaw as high severity. The EPSS score of less than 1% indicates a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to craft a URL or input that is reflected by the plugin and persuade a user to visit it, which is a typical reflected XSS attack vector.
OpenCVE Enrichment
EUVD