Impact
The vulnerability is a Reflected Cross‑Site Scripting flaw caused by improper neutralization of input in the SyncFields plugin for WordPress. This weakness, identified as CWE‑79, allows malicious JavaScript to be reflected in a page that is served to users when crafted input is incorporated into the HTML output. The flaw results solely from crafted input that is returned directly in the response.
Affected Systems
The affected product is the pjfc SyncFields WordPress plugin of any version up to and including 2.1. No earlier version constraint is specified; therefore any deployment using version 2.1 or an earlier release is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of <1% indicates a very low likelihood of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote, requiring the attacker to supply crafted input (URL or form data) that triggers the reflected output.
OpenCVE Enrichment
EUVD