Impact
The vulnerability is an instance of improper neutralization of input during web page generation, allowing the plugin to reflect unsanitized user data in responses. An attacker can craft a URL containing malicious JavaScript that, when executed in the victim’s browser, results in a reflected XSS attack. This flaw may enable session hijacking, credential theft, or defacement of the site. The weakness is identified as CWE‑79.
Affected Systems
WordPress sites that have the Opentracker Analytics plugin installed at version 1.3 or earlier. The problem affects all releases from the plugin’s inception through 1.3.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity vulnerability. The EPSS score being below 1% suggests a low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to deliver a malicious link to a user; the user must then visit the link for the XSS payload to be executed. No remote code execution or privilege escalation is possible directly from the vulnerability, but the impact can be significant if an attacker controls the victim’s session or tampered content.
OpenCVE Enrichment
EUVD