Impact
The Media Category Library plugin contains a reflected cross‑site scripting (XSS) flaw caused by improper neutralization of user input during web page generation. An attacker could embed malicious scripts in request parameters that are reflected back in the page output, potentially allowing client‑side scripts to execute in the victim’s browser. The weakness is categorized as CWE‑79 and is limited to reflected XSS, not affecting the server side logic directly.
Affected Systems
Affected are all versions of the Media Category Library plugin by timmcdaniels up to and including 2.7. No specific version numbers beyond the upper boundary are listed, so any installation running 2.7 or earlier is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis. The entry is not listed in the CISA KEV catalog. Based on common XSS exploitation patterns, the likely attack vector is a crafted URL or form submission that the application reflects in its page output, allowing an attacker to trick a user into visiting the malicious link. No specific environmental constraints are listed, so the flaw can be leveraged by any user who views a page that includes the vulnerable parameter.
OpenCVE Enrichment
EUVD