Impact
Improper neutralization of input during web page generation allows an attacker to inject and execute arbitrary scripts when a victim visits a crafted URL. This reflected XSS flaw in the WP‑tagMaker plugin can lead to session hijacking, defacement, or delivery of malware within the victim’s browser context. The vulnerability is categorized as a Cross‑Site Scripting weakness (CWE‑79) and specifically affects plugin versions up to 0.2.2.
Affected Systems
The affected product is the WordPress plugin WP‑tagMaker developed by lich_wang. Versions from the initial release through 0.2.2 are vulnerable. Any WordPress installation that has this plugin enabled, especially those running the indicated versions, is at risk.
Risk and Exploitability
With a CVSS score of 7.1 and an EPSS score of less than 1 %, the exploit probability is low but not negligible. The attack vector is web‑based reflected XSS, meaning an attacker must entice a victim to visit a specially crafted link or input that the plugin reflects without proper sanitization. Because the flaw is not listed in the CISA KEV catalog, there is no current evidence of active exploitation, but the high integrity impact of the flaw warrants prompt review.
OpenCVE Enrichment
EUVD