Impact
The Social Pug: Author Box plugin contains an improper input neutralization flaw that allows Reflected Cross‑Site Scripting (XSS). An attacker can supply malicious JavaScript via reflected input, which is then injected into the HTML output, enabling session hijacking, defacement, or data theft from the victim's browser. This flaw is classified as CWE‑79 and can affect confidentiality, integrity, and availability of the web application.
Affected Systems
The vulnerability is present in all releases of the plugin up through version 1.0.0. The affected product is WordPress Social Pug: Author Box, maintained by iova.mihai. No other vendors or products are mentioned.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% shows that the probability of exploitation in the wild is low, and it is not listed in the CISA KEV catalog, suggesting limited known exploitation. Rationally, the attack vector is likely a crafted URL or form input that the plugin reflects in a page. An attacker does not need special access, but must be able to cause a victim to load the malicious payload, for example by sending a link via email or embedding it on a page.
OpenCVE Enrichment
EUVD