Impact
The vulnerability is a Reflected Cross‑Site Scripting flaw in the WordPress WP PT‑Viewer plugin caused by improper input neutralization in generated web pages, allowing an attacker to inject and execute arbitrary JavaScript while a victim views a crafted page. This could enable session hijacking, defacement, or malicious payload delivery within the victim’s browser context.
Affected Systems
Vendors: Vincent Mimoun‑Prat – product WP PT‑Viewer. All installations of the plugin with a version of 2.0.2 or earlier are vulnerable. The flaw is present in every release up to 2.0.2.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact, but the EPSS score of less than 1% reflects a low current exploitation probability, and the issue is not listed in the CISA KEV catalog. The flaw is typically exploited remotely by sending a malicious link that contains tampered parameters to a user who then visits the page, causing client‑side script execution. Because it is a reflected XSS, an attacker only needs the victim to load a crafted page; no prior authentication is required, making it relatively easy to launch but limited to the victim’s browser session.
OpenCVE Enrichment
EUVD