Impact
The vulnerability is a reflected cross‑site scripting flaw in the NsThemes NS Simple Intro Loader plugin. The plugin fails to properly neutralize user‑supplied input before rendering it on a web page, allowing an attacker to inject malicious script that executes in the browsers of users who request specific URLs. This can lead to theft of session cookies, defacement, or redirection to malicious sites, compromising confidentiality and user trust.
Affected Systems
The plugin NS Simple Intro Loader, distributed by NsThemes, is affected on all installations using version 2.2.3 or earlier. Users whose sites rely on the plugin should verify the installed version and consider upgrading promptly.
Risk and Exploitability
The CVSS score of 7.1 indicates high potential severity. An EPSS score of less than 1% suggests low but non‑zero likelihood of exploitation; however, the fact that the vulnerability is not listed in the CISA KEV catalog does not eliminate risk. The likely attack vector is a crafted request that includes malicious input in a URL parameter that the plugin reflects in its output. Attackers can exploit this from any internet‑connected browser without authentication, so the risk is present for public‑facing sites.
OpenCVE Enrichment
EUVD