Impact
The flaw is an improper neutralization of input during web page generation that permits reflected cross‑site scripting. An attacker can supply crafted input that is reflected in a page without adequate escaping, allowing malicious code to execute in the browser of any user who views the affected page.
Affected Systems
The WPEX Replace DB Urls WordPress plugin developed by dstoever is affected for all releases from the earliest version through 0.4.0. Sites running these plugin versions on any WordPress installation are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high severity. The EPSS score of less than 1 % indicates a low overall exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via the web interface, as the flaw is triggered by user‑supplied input that is rendered without proper escaping.
OpenCVE Enrichment
EUVD