Impact
The vulnerability is a reflected cross‑site scripting flaw caused by insufficient input validation when generating web pages. An attacker can craft a malicious URL or form input that, when processed by the plugin, injects executable script into the page. This allows the attacker to run arbitrary JavaScript in a victim's browser session, potentially leading to session hijacking, credential theft, or phishing landing pages. The weakness corresponds to CWE‑79.
Affected Systems
The affected vendor is Bilal TAS, delivering the Responsivity plugin for WordPress. Versions from any unspecified version (n/a) through and including 0.0.6 are affected. Users running the plugin at or below 0.0.6 are vulnerable; later releases are presumed fixed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% suggests exploitation is unlikely at this time, and the CVE is not listed in CISA's KEV catalog. Attackers would exploit the flaw via a user visiting a specially crafted URL or clicking a malicious link that triggers the plugin’s processing of the untrusted input. No additional conditions or authentication are required, making the attack vector straightforward.
OpenCVE Enrichment
EUVD