Impact
The vulnerability is an improper neutralization of input during web page generation, allowing reflected XSS attacks. An attacker can inject malicious scripts into the page output, which are executed in the browser of any user who visits a specially crafted URL. This can lead to session hijacking, defacement, or illicit data exfiltration. The weakness is identified as CWE‑79.
Affected Systems
WordPress users of the Redux Converter plugin by David Anderson / Team Updraft are affected. All releases from the earliest version up to and including 1.1.3.1 have the flaw; newer releases are presumed fixed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity with substantial impact. The EPSS score is below 1%, suggesting low current exploitation activity, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is most likely a reflected XSS via a crafted link or query parameter presented to the user; no elevated privileges or network access are required.
OpenCVE Enrichment
EUVD