Impact
The ULTIMATE VIDEO GALLERY plugin contains an improper neutralization of input vulnerability that allows attackers to inject malicious scripts into web pages via user‑supplied parameters, potentially enabling reflected cross‑site scripting that can steal session cookies, deface content, or redirect users.
Affected Systems
This vulnerability affects all versions of the extendyourweb ULTIMATE VIDEO GALLERY plugin up to and including 1.4; versions prior to the earliest available version may also be impacted if they share the same code base.
Risk and Exploitability
With a CVSS score of 7.1, the exploit is considered high‑to‑moderate severity. The EPSS score indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to craft a malicious link that a victim clicks, after which the reflected script will execute in the victim's browser. Therefore, the risk is significant for sites that expose the vulnerable plugin to external users.
OpenCVE Enrichment
EUVD