Impact
The vulnerability stems from improper neutralization of user input during web page rendering, allowing attackers to inject malicious scripts that are reflected back to the victim's browser. Based on the description, the likely attack vector is a crafted URL input to the web interface, as the description explicitly mentions reflected XSS. Exploitation can result in session hijacking, cookie theft, or the launch of additional malicious payloads, effectively compromising the confidentiality and integrity of the user session.
Affected Systems
The affected software is the Explara Membership plugin for WordPress, version 0.0.7 and older. Vendors: Explara. The plugin functions as a membership management tool within WordPress installations; any host running these versions is susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of <1% shows a low likelihood of active exploitation. The vulnerability is accessible through the web interface, typically via a crafted URL that includes malicious script payloads. Because the issue is not listed in the CISA KEV catalog, there is no evidence of widespread attacks yet, but the potential for user‑targeted phishing or malicious link delivery remains.
OpenCVE Enrichment
EUVD