Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation flaw that permits reflected Cross‑Site Scripting. An attacker can supply malicious input that is reflected back into the HTML of the page, which can be used to execute arbitrary JavaScript in the victim’s browser. The weakness corresponds to CWE-79 and can compromise confidentiality and integrity of user data or allow session hijacking.
Affected Systems
The flaw resides in the Trustist TRUSTist REVIEWer WordPress plugin. Versions up to and including 2.0 are affected; versions beyond 2.0 are assumed to be unaffected. Any WordPress site that has this plugin installed is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% suggests that, at the current time, exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve a victim clicking a crafted link or submitting input to a vulnerable form; the attacker does not need elevated privileges but requires the victim’s browser to render the malicious payload. No patch is publicly published, so the mitigation relies on updating, disabling, or applying defensive controls.
OpenCVE Enrichment
EUVD