Impact
Improper neutralization of input during web page generation in the WP Login Attempt Log plugin allows reflected cross‑site scripting; an attacker can inject arbitrary JavaScript that is returned to the browser in the subsequent page load. This flaw is a typical CWE‑79 violation.
Affected Systems
The vulnerability affects the fredsted WP Login Attempt Log plugin for WordPress, versions from the earliest release through 1.3, inclusive. Any WordPress site that has this plugin installed is potentially exposed.
Risk and Exploitability
The CVSS score of 7.1 is classified as high severity according to the CVSS categories, while the EPSS score of less than 1 % indicates that widespread exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector involves a crafted URL or form input that the plugin reflects back into the page; an attacker may embed malicious scripts in such a payload and entice a user to load the resulting link or submission.
OpenCVE Enrichment
EUVD