Impact
The vulnerability is a reflected cross‑site scripting flaw that allows an attacker to inject malicious scripts directly into pages that are served to users. Once executed, the script can steal session cookies, deface the site, or launch further attacks against site visitors. The weakness stems from improper neutralization of user input during web page generation, as identified by CWE‑79.
Affected Systems
This flaw is present in the WordPress plugin Userbase Access Control by David Cramer, affecting all installed copies with versions 1.0 and earlier. The plugin is distributed through the WordPress ecosystem and can be found on sites running any WordPress version where the plugin is active.
Risk and Exploitability
The CVSS score of 7.1 indicates high damage potential with a medium-level attack vector. The EPSS score of < 1% shows that, at the time of this analysis, real‑world exploitation evidence is very low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only that an attacker craft a URL or form that reflects user input to the victim’s browser, making the attack vector largely web‑based and user‑interaction‑dependent.
OpenCVE Enrichment
EUVD