Impact
The vulnerability is an improper neutralization of user input before rendering it in the web page, allowing a reflected XSS flaw that can execute arbitrary client‑side code. This weakness is classified as CWE‑79 and can be used to steal session cookies, deface content or redirect users to malicious sites, affecting the confidentiality and integrity of the victim’s session data.
Affected Systems
Jonathan Lau’s CubePM WordPress plugin, versions 1.0 and earlier, is affected.
Risk and Exploitability
The CVSS score of 7.1 places the flaw in the high severity range, indicating a serious threat if exploited. However, the EPSS score of less than 1% suggests that, at present, the likelihood of real‑world exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a crafted URL or form input that contains malicious script, which is reflected back in the response without proper encoding.
OpenCVE Enrichment
EUVD