Impact
The plugin does not properly escape or encode user-supplied input before rendering it in a page, allowing a malicious actor to inject arbitrary HTML or JavaScript into the response. When a victim visits a crafted URL, the code executes in that user’s browser, potentially enabling session hijacking, credential theft, or site defacement.
Affected Systems
The flaw exists in the Hesabfa Accounting WordPress plugin from Saeed Sattar Beglou. Any installation utilizing versions from the earliest release through 2.1.2 is affected.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests a low exploitation probability and the vulnerability is not listed in CISA’s KEV catalog. The attack surface is remote and could be exploited through a crafted link, meaning phishing or social engineering campaigns may successfully deliver malicious scripts to users of the affected plugin.
OpenCVE Enrichment
EUVD