Impact
The vulnerability is an improper neutralization of input during web page generation, allowing an attacker to inject malicious script content that is reflected back to the user. At its core, it is a reflected XSS flaw that could permit an attacker to execute arbitrary scripts in the victim’s browser, facilitating phishing, session hijacking, or defacement. The weakness is classified as CWE‑79 and carries a CVSS score of 7.1, indicating a high impact on confidentiality, integrity, and availability for affected users.
Affected Systems
The issue affects the WordPress Smooth Dynamic Slider plugin developed by Kundan Yevale, specifically versions from unlisted earlier releases up through 1.0. Any installation of the plugin within that version range is vulnerable.
Risk and Exploitability
The EPSS score of less than 1% suggests a low probability of exploitation in the wild at present, and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation. Nonetheless, the attack vector is likely through a crafted URL or form input that is echoed in a page response, a typical scenario for reflected XSS. Given the high CVSS score, if an attack were to succeed, it could lead to compromise of user sessions or site defacement.
OpenCVE Enrichment
EUVD