Impact
Improper neutralization of script‑related HTML tags allows a reflected XSS flaw that can be triggered via crafted input or URLs, enabling an attacker to inject malicious scripts into a victim’s browser. This can lead to session hijacking, defacement, or phishing attacks. The weakness is classified as CWE‑80, indicating a failure in input validation and escaping.
Affected Systems
The Vulnerability affects the "Improve My City" WordPress plugin for all releases up to and including version 1.6, as identified by the plugin author. All installations using 1.6 or earlier are impacted; newer releases are presumed fixed.
Risk and Exploitability
The CVSS score of 7.1 denotes a moderate‑to‑high severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is reflected in user-supplied data, so an attacker can craft a malicious link that, when visited, executes scripts in the context of the victim’s browser.
OpenCVE Enrichment
EUVD