Impact
Improper neutralization of user‑supplied input during page generation allows an attacker to inject and execute malicious JavaScript in the context of the website, potentially leading to session hijacking, phishing, or arbitrary code execution on the client side. The vulnerability is a classic reflected XSS flaw categorized under CWE-79.
Affected Systems
The flaw exists in the ianhaycox World Cup Predictor WordPress plugin, affecting all releases from the initial version through 1.9.8 inclusive. Any WordPress site that has this plugin installed and exposes the vulnerable input via a URL is at risk; no specific WordPress core versions are mentioned.
Risk and Exploitability
The CVSS base score of 7.1 indicates moderate severity, while the EPSS score of less than 1 % suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is a crafted URL that, when visited by a user, causes the browser to execute the injected script.
OpenCVE Enrichment
EUVD