Impact
The vulnerability is a reflected XSS flaw caused by improper neutralization of input during page generation. Attackers can inject malicious scripts that execute in the browsers of site visitors, enabling credential theft, session hijacking, or defacement of the site content.
Affected Systems
The flaw exists in the WordPress Quizzin plugin from binnyva, affecting all instances with a version of 1.01.4 or older. No earlier baseline version is known, so any installation using the vulnerable release is at risk.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability carries a high severity, yet its EPSS score is below 1 %, indicating a low likelihood of exploitation in the wild and it is not listed in CISA’s KEV catalog. Attackers could craft a URL or input containing a malicious payload that, when reflected by the plugin, runs client‑side code in the target browser. The vulnerability does not require authentication and operates remotely.
OpenCVE Enrichment
EUVD