Impact
The ntp-header-images plugin contains an improper neutralization of input during web page generation, enabling reflected XSS attacks. An attacker can inject malicious scripts into the plugin’s output by providing crafted parameters in a URL or form submission, leading to potential cookie theft, session hijacking, or defacement of the website. The vulnerability requires that the injected content be rendered in the browser of a user who views the compromised page.
Affected Systems
WordPress installations running the nord_tramper ntp-header-images header-images-rotator plugin version 1.2 or earlier are affected. The plugin’s functionality may be invoked on any page that displays user‑generated content or uses the plugin’s shortcodes.
Risk and Exploitability
With a CVSS score of 7.1, the flaw is considered a high‑severity issue. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a web‑based input path, such as a request URL parameter or form field that the plugin fails to sanitize before rendering.
OpenCVE Enrichment
EUVD