Impact
An improper neutralization of user input during page rendering in the Claire Ryan Author Showcase plugin enables reflected cross‑site scripting. When a user accesses a crafted URL or input that the plugin fails to sanitize, it echoes that input back in the generated page, allowing arbitrary JavaScript to run in the victim’s browser.
Affected Systems
The plugin for WordPress developed by Claire Ryan, known as Author Showcase, is vulnerable in all releases up to and including version 1.4.3. Any WordPress site still running one of those versions contains the flaw.
Risk and Exploitability
The CVSS base score of 7.1 classifies the flaw as high severity. The EPSS score of less than 1 % indicates that, at the time of analysis, the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread, confirmed exploitation. An attacker can trigger the reflected XSS by delivering a malicious URL or input to a user who has the vulnerable plugin’s page rendered; no server‑side compromise is required.
OpenCVE Enrichment
EUVD