Impact
The Envato Affiliater plugin contains an improper neutralization of input during web page generation, allowing reflected XSS. An attacker can inject JavaScript that the plugin reflects back into the page, enabling execution of malicious scripts in the victim’s browser, a flaw classified as CWE‑79.
Affected Systems
WordPress sites that have the Envato Affiliater plugin version 1.2.4 or older are affected. The vendor is khaninejad and the product name is Envato Affiliater. No further version details are available beyond the <= 1.2.4 limit.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as High severity. The EPSS score of less than 1% indicates that exploitation attempts are currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Based on the nature of reflected XSS, the likely attack vector is remote through a crafted URL that the plugin processes and reflects without proper escaping.
OpenCVE Enrichment
EUVD