Impact
The vulnerability is a reflected XSS flaw located in GrandSlambert's Featured Page Widget plugin. An attacker can supply malicious input that is not properly escaped or encoded in the HTTP response, allowing them to inject arbitrary client‑side scripts into the page viewed by any user. This weakness is classified as CWE‑79 and can enable malicious payloads to run in the victim’s browser in the context of the affected site.
Affected Systems
The affected system is the WordPress plugin Featured Page Widget from GrandSlambert, with all versions up to and including 2.2 vulnerable.
Risk and Exploitability
The vulnerability is present in all plugin installations through version 2.2 and carries a CVSS score of 7.1. Its EPSS score is less than 1%, indicating a low current exploitation probability, and it is not yet listed in the CISA KEV catalog. Exploitation would require an attacker to craft a URL or form input that includes malicious JavaScript, which a user would need to visit or submit. The flaw enables session‑cookie theft, phishing, or other client‑side attacks executed within the site’s domain.
OpenCVE Enrichment
EUVD