Impact
Improper neutralization of input during web page generation allows an attacker to inject malicious JavaScript that is reflected back to the victim’s browser. This reflected cross‑site scripting can lead to theft of user credentials, session hijacking, and defacement of the site, compromising confidentiality and integrity of sensitive data.
Affected Systems
The vulnerability affects the WordPress plugin Vicente Ruiz Gálvez VR‑Frases version 4.0.1 and all earlier releases (from the initial release through 4.0.1). Site owners running these plugin versions are directly impacted.
Risk and Exploitability
The CVSS score of 8.2 underscores the high severity of the flaw. The EPSS score of less than 1% indicates a low probability of exploitation in the broader threat landscape, and the issue is not listed in the CISA KEV catalog. Nonetheless, because the vulnerability is reflected, a malicious link can be sent to unsuspecting users, making it a significant threat if users visit compromised URLs. Damage depends on the privilege level of the victim and the value of the data exposed through the injected script. The attack vector is client‑side via the web browser. Even with a low EPSS, resolving the flaw promptly remains a priority for maintaining web application security.
OpenCVE Enrichment
EUVD