Impact
The vulnerability is a reflected XSS flaw identified as CWE‑79, where untrusted input is incorporated into web pages. An attacker can supply malicious JavaScript via a crafted request that the plugin echoes back, enabling execution in the victim’s browser. The impact includes session hijacking, credential theft, or defacement of the site as the attacker gains the victim’s privilege level.
Affected Systems
The flaw affects the baonguyenyam WOW Best CSS Compiler plugin for WordPress version 2.0.2 and earlier. WordPress sites that have installed any of these plugin versions are vulnerable. The exact affected version range is from the initial release up to and including 2.0.2.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% shows that exploitation is considered low probability at present. The vulnerability is not listed in CISA KEV, meaning no publicly known exploitation campaigns. The likely attack vector is a web request to a page that includes plugin‑controlled parameters; based on the description, it is inferred that remote attackers can execute arbitrary scripts if the target site does not implement proper input validation or output encoding.
OpenCVE Enrichment
EUVD