Impact
The vulnerability is caused by improper input sanitization in the WordPress Signature plugin, causing user‑controlled data to be reflected unencoded in a web page. An attacker can inject malicious JavaScript that is executed in the victim’s browser, potentially allowing cookie theft, phishing, or page defacement. This flaw is classified as CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
All WordPress sites that have installed the WordPress Signature plugin by Abinav Thakuri in versions up to and including 0.1 are affected. Any site running this plugin revision is vulnerable regardless of WordPress core version.
Risk and Exploitability
The CVSS score is 7.1, indicating a medium‑to‑high impact. The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting low exploitation probability at present. Nevertheless, the flaw can be exploited remotely via crafted URLs or form submissions that echo payloads back to the browser; attackers can easily construct these requests, so the risk remains significant until mitigated.
OpenCVE Enrichment
EUVD