Impact
The vulnerability is improper neutralization of input when generating a web page, allowing attackers to inject malicious JavaScript into responses. This reflected XSS can enable session hijacking, defacement, or phishing attempts for users who view the affected page. The weakness corresponds to CWE‑79.
Affected Systems
The flaw affects the WordPress "Partners" plugin distributed by farinspace, all released versions up through 0.2.0. Any installation of the plugin on a WordPress site is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑high severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation and the vulnerability is not listed in the CISA KEV catalog. It is inferred that the flaw can be triggered by supplying crafted input through the plugin's parameters in a HTTP request, which does not require authentication, allowing an attacker to inject malicious JavaScript.
OpenCVE Enrichment
EUVD