Impact
The DevriX DX Sales CRM WordPress plugin contains an improper neutralization of user input during page generation, which allows reflected XSS. An attacker can embed arbitrary scripts that are reflected back to the user as part of the web page. The weakness is classified as CWE‑79. The vulnerability exists in all plugin versions up to and including 1.1 and is present in every release from the earliest version through <= 1.1.
Affected Systems
All installations of the DevriX DX Sales CRM WordPress plugin at version 1.1 or earlier are affected. The issue applies from the earliest released version up through 1.1. The vendor listed in the vulnerability is DevriX.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity. The EPSS score of < 1% suggests a low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a reflected XSS scenario where malicious content is supplied via a web request and rendered unsafely, without requiring credential compromise and potentially affecting any user who visits a crafted URL or form.
OpenCVE Enrichment
EUVD