Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation (CWE‑79) in the WordPress plugin Download, Downloads (ydn‑download). It allows attackers to inject malicious script that is reflected back to the victim’s browser when the plugin processes user‑supplied data. The impacted code path outputs unsanitized input, enabling arbitrary JavaScript execution in the context of the site.
Affected Systems
Any WordPress installation that has the Download, Downloads plugin from edmon.parker with a version of 1.4.2 or earlier is affected. The issue is present in all releases up to and including 1.4.2.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of this reflected XSS flaw. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a crafted URL or form submission that includes malicious script targeting the plugin’s input fields, which is reflected back to the user. Given the moderate exploitation probability, sites should prioritize patching.
OpenCVE Enrichment
EUVD