Impact
Improper neutralization of input during web page generation allows a DOM-based XSS flaw in the Surbma | Premium WP plugin. An attacker can inject malicious script that executes in the victim's browser when the vulnerable page is loaded. The vulnerability carries a CVSS score of 6.5, indicating medium severity.
Affected Systems
The vulnerability affects the Surbma | Premium WP plugin from version n/a through 9.0. An attacker can target any WordPress site that has installed Surbma | Premium WP version 9.0 or earlier.
Risk and Exploitability
The EPSS score of less than 1% suggests a low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to trigger the plugin’s DOM processing path, typically by supplying crafted input or a malicious link that causes the victim’s browser to execute the injected script. The vulnerability is remotely exploitable through a web browser.
OpenCVE Enrichment
EUVD