Impact
The vulnerability allows an attacker to inject malicious script payloads into the web page generated by the Yashar Texteller WordPress plugin. This reflected cross‑site scripting can lead to theft of user cookies or tokens, session hijacking, redirection to malicious sites, and potential defacement of the compromised site. These effects expose both confidentiality and integrity of data within the affected instance.
Affected Systems
WordPress sites that use the Yashar Texteller plugin version 1.3.0 or earlier are vulnerable. The plugin is a third‑party component that can be installed by site administrators and integrated into any WordPress installation.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers may exploit the flaw remotely by constructing a crafted request that includes malicious script content directed at the plugin’s input fields or URL parameters. The lack of additional mitigations on the vulnerable code base makes the exploitation path straightforward for a determined attacker.
OpenCVE Enrichment
EUVD