Impact
Improper neutralization of user input during web page generation allows a reflected cross‑site scripting (XSS) flaw. An attacker can embed malicious JavaScript within a crafted URL or form, which will be executed in the context of victim browsers when the page loads. This CWE‑79 vulnerability can lead to session hijacking, defacement, or phishing attacks.
Affected Systems
WordPress sites running the LH Login Page plugin by shawfactor with any release up to and including version 2.14 are affected. The issue is present in all stated versions (from unknown through 2.14).
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, but the EPSS score of less than 1% suggests a low likelihood of current exploitation. The plugin is web‑based, so an attacker only needs to lure a victim to a malicious link; no privileged access is required. The vulnerability is not listed in CISA's KEV catalog. Although exploitation probability is low, the impact on confidentiality and integrity of user sessions can be substantial if a progressive or social‑engineering campaign is used.
OpenCVE Enrichment
EUVD