Impact
This vulnerability allows attackers to embed malicious scripts into web pages rendered by the LucidLMS plugin for WordPress. The flaw resides in inadequate input sanitization during page generation, giving rise to reflected XSS. An attacker who successfully exploits this flaw can execute arbitrary code in the browser of a victim who visits a crafted URL, potentially leading to credential theft, session hijacking or defacement. The weakness is classified as CWE‑79.
Affected Systems
The affected product is the LucidLMS plugin developed by N3wNormal. Versions from the first release through version 1.0.5 are vulnerable. Any WordPress installation that has LucidLMS up to and including v1.0.5 installed is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. The EPSS score of less than 1% suggests that public exploitation is currently uncommon, but does not eliminate the risk. The issue is not listed in the CISA KEV catalog, which implies no known widespread exploitation at the time of this analysis. Attackers would typically craft a URL containing malicious payloads and entice a user to visit that link. If a victim’s browser processes the response from the web server, the script runs under the victim’s context. This provides a relatively low barrier to exploitation in terms of prerequisites, making the vulnerability a concern for any site exposing the plugin to users.
OpenCVE Enrichment
EUVD