Impact
Improper neutralization of input during web page generation allows an attacker to inject malicious scripts that are reflected back to users who load the affected page. This promotes compromise of user credentials, defacement, or execution of arbitrary code in the victim's browser. The weakness is classified as CWE‑79 and can lead to confidentiality and integrity violations when users interact with the compromised content.
Affected Systems
The vulnerability affects the WordPress plugin idiatech Catalog Importer, Scraper & Crawler known as intelligent‑importer. All releases through version 5.1.3 are affected; no later releases are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is inferred to be network based, with an attacker submitting crafted data to the plugin’s import or scraping interfaces, which is then rendered directly in the browser of any user who accesses the output. Because the flaw is reflected, the attacker does not need persistent access or privileged credentials to exploit it.
OpenCVE Enrichment
EUVD