Impact
Improper neutralization of input during web page generation allows a reflected cross‑site scripting attack in the Kikx Simple Post Author Filter plugin. The flaw, identified as CWE‑79, can inject malicious scripts into pages served to site visitors, potentially compromising user sessions or defacing content.
Affected Systems
The vulnerability affects the asokaaso2 Kikx Simple Post Author Filter WordPress plugin, versions up to and including 1.0. Any site that has installed this plugin and has it enabled is susceptible.
Risk and Exploitability
With a CVSS score of 7.1 and an EPSS score of less than 1%, the likelihood of exploitation in the wild is low, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be a crafted URL or form input that the plugin echoes back to the browser without proper encoding, allowing an arbitrary attacker to execute JavaScript in the context of visitors. Such exploitation could lead to session hijacking, data theft, or site defacement.
OpenCVE Enrichment
EUVD