Impact
The vulnerability is an improper neutralization of user‑supplied data during page rendering, allowing an attacker to inject and execute arbitrary JavaScript in a victim’s browser whenever they visit a crafted URL. Because the plugin reflects the supplied input directly into HTML without proper escaping, an attacker can supply malicious code that triggers on the next page load, potentially compromising the victim’s session, stealing credentials, or redirecting to malicious sites.
Affected Systems
WordPress sites that have the Off Page SEO plugin by Jakub Glos installed at version 3.0.3 or earlier are affected. Any system running that plugin will honor user‑supplied input in URLs or form submissions and is therefore vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact, but the EPSS score of less than 1% shows that exploitation is currently considered low probability and the vulnerability is not listed in CISA’s KEV catalog. Attackers would likely use a drive‑by or phishing technique, embedding a malicious link that renders the reflected script in the context of the victim’s browser. Since the flaw does not require authentication or higher privileges, any user visiting a crafted link can be affected.
OpenCVE Enrichment