Impact
The vulnerability is an improper neutralization of input during page generation that allows an attacker to inject and execute arbitrary JavaScript within the context of the victim’s browser. As a result, an attacker can hijack user sessions, deface the site, or exfiltrate credentials. This is a classic reflected XSS flaw classified as CWE‑79.
Affected Systems
The issue affects the rachanaS Sponsered Link WordPress plugin version 4.0 and earlier. Users running this plugin on any WordPress installation are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, but the EPSS score of less than 1% suggests a low probability of exploitation at the moment. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation is likely possible through crafted URLs or user‑supplied parameters, but the attacker requires user interaction to trigger the reflected payload.
OpenCVE Enrichment
EUVD