Impact
The Nativery WordPress plugin contains a DOM‑based XSS flaw caused by improper neutralization of input during web page generation. An attacker could inject malicious scripts into pages served by the plugin, leading to client‑side code execution. Based on common XSS effects, this could potentially allow a user to hijack sessions, deface content, or exfiltrate data, however the CVE description does not explicitly state these outcomes.
Affected Systems
This vulnerability affects WordPress sites that have the Nativery plugin version 0.1.6 or earlier. All installations of the plugin within this range are at risk whenever the plugin processes user input.
Risk and Exploitability
The flaw has a CVSS score of 6.5, indicating moderate severity. The EPSS score is less than 1 %, suggesting a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is client‑side DOM manipulation requiring an end‑user to visit a page or interact with input that triggers the plugin’s processing; therefore active user interaction is generally needed for exploitation.
OpenCVE Enrichment
EUVD