Impact
This vulnerability is an improper neutralization of input during web page generation. The Essay Wizard (wpCRES) plugin accepts user input that is reflected in the generated page without proper sanitization, allowing malicious script payloads to execute in the context of a victim’s browser. The attacker can inject arbitrary JavaScript code, potentially hijacking user sessions, defacing content, or conducting phishing attacks against site users. The weakness is catalogued as CWE‑79.
Affected Systems
WordPress sites that have the wrenchpilot Essay Wizard (wpCRES) plugin installed, versions from the earliest (n/a) through 1.0.6.4 are vulnerable. Any site using those plugin versions is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity exploitation potential. The EPSS score of less than 1% implies that active exploitation is unlikely but possible. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a crafted URL that includes malicious input to be reflected by the plugin’s output; when a user navigates to that URL, the payload runs in the user’s browser. The impact is limited to the victim’s session, but can lead to credential theft or further website compromise.
OpenCVE Enrichment
EUVD