Impact
The vulnerability is a reflected cross‑site scripting flaw that arises when user input is not properly neutralized before being returned in a web page. An attacker can craft a request containing malicious script that is reflected back to the victim’s browser, enabling the execution of arbitrary JavaScript in the context of the site. This can lead to session hijacking, credential theft, or other client‑side attacks. The weakness is classified as CWE‑79.
Affected Systems
The affected product is the WordPress Lijit Search plugin (damniel) version 1.1 and earlier. Any WordPress site that has this plugin installed is vulnerable. No specific core WordPress versions are mentioned as impacted, and the issue applies to all installations of the plugin prior to the fix.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The flaw is not listed in CISA’s KEV catalog. Attackers can exploit it remotely by sending a crafted HTTP request to the plugin’s endpoint; the malicious payload is echoed back to the victim’s browser, triggering execution if the user clicks a malicious link or visits a crafted URL.
OpenCVE Enrichment
EUVD