Impact
An improper neutralization of input during web page generation within the Chris Taylor Wibstats plugin allows attackers to inject and execute arbitrary script code that is reflected back to the victim’s browser. The resulting reflected XSS can enable cookie theft, session hijacking, or other malicious actions performed in the context of the victim’s authenticated session. The weakness is classified as CWE‑79.
Affected Systems
Any WordPress installation that has the Wibstats statistics for WordPress MU plugin installed and running the vulnerable version series up to and including 0.5.5. The issue is present from the initial release through the 0.5.5 release version.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known large‑scale exploitation yet. The likely attack vector involves an attacker crafting a malicious URL that exploits the reflected XSS; the victim must then interact with the URL, such as clicking a link in an email or social media post. Exploitation requires only user interaction and does not provide broader system compromise.
OpenCVE Enrichment
EUVD