Impact
The vulnerability allows an attacker to inject malicious scripts into pages that are served to users. By exploiting improper input neutralization, an attacker can embed code that executes in the victim’s browser when the crafted request is processed. This can lead to theft of session cookies, credential compromise, defacement, or malicious redirects, directly affecting confidentiality, integrity, and availability of user data and trust in the site.
Affected Systems
Cojecto Predict When plugin, versions from any earlier release through 1.3 are affected. The vulnerability exists in the Predict When plugin deployed within WordPress sites.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, but the EPSS score below 1% shows a low likelihood of exploitation at present. The attack can be performed via reflected XSS, requiring the victim to visit a crafted URL or interaction with malicious content on the site. The plugin is not listed in the CISA KEV catalog, so no confirmed widespread exploitation has been reported yet.
OpenCVE Enrichment
EUVD