Impact
The Push Envoy Notifications plugin for WordPress allows reflected cross‑site scripting because user input is not properly escaped before rendering in a page. An attacker can deliver a crafted URL that injects JavaScript into the browser of anyone who visits it, potentially leading to cookie theft, session hijacking, or defacement of the site. This flaw is a CWE‑79 "Improper Neutralization of Input During Web Page Generation" type vulnerability.
Affected Systems
netbitsolutions Push Envoy Notifications plugin, WordPress, versions n/a through 1.0.0. Any WordPress site using this plugin prior to version 1.0.0 is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high risk, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote, via a crafted URL that an unsuspecting user clicks or is otherwise exposed to, which then injects malicious script into the victim’s browser.
OpenCVE Enrichment
EUVD