Impact
Improper neutralization of user input in the Sleekplan WordPress plugin results in the injection of malicious JavaScript that is reflected back to users viewing affected content. This is a Reflected Cross‑Site Scripting vulnerability (CWE‑79). The CVE does not specify additional data compromise or other consequences beyond the script execution on the client side.
Affected Systems
Any installation of the Sleekplan plugin from an unspecified starting point up to and including version 0.2.0. Site administrators should verify whether their WordPress instance is running a vulnerable version and plan an update if necessary.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity vulnerability. The EPSS score is less than 1 %, indicating a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves delivering a crafted URL that includes a malicious script payload via the plugin’s query parameters; this inference is based on the nature of reflected XSS and the absence of explicit attack vector details in the description. Despite the low exploitation probability, the impact warrants timely remediation.
OpenCVE Enrichment