Impact
Improper neutralization of input during web page generation leads to reflected cross‑site scripting in the Site PIN plugin. This flaw allows an attacker to inject malicious script that executes in the browser of any user who views the crafted URL. The impact is the compromise of confidentiality and integrity of user data and potential phishing or credential theft, but it does not provide a direct path to remote code execution.
Affected Systems
Vulnerable versions of the Marcus Downing Site PIN plugin run on WordPress sites. The flaw applies to all releases from the initial public version up to and including 1.3. Sites that have installed any of these versions are susceptible.
Risk and Exploitability
The CVSS base score is 7.1, indicating high severity, while the EPSS score is below 1 %, showing a low but non‑zero probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation typically requires the attacker to entice a user to click a crafted link containing the malicious script, so it is considered a user‑device–directed attack.
OpenCVE Enrichment
EUVD