Impact
The vulnerability is an improper neutralization of input during web page generation, allowing malicious code to be reflected in the rendered page. It is a classic Cross‑Site Scripting flaw (CWE‑79). An attacker could inject JavaScript that executes in the victim’s browser, enabling session hijacking, defacement, or delivery of malware. The flaw exists in the ContentOptin Lite plugin when processing user input that appears on the output page.
Affected Systems
The affected product is the WordPress plugin ContentOptin Lite provided by markugwuanyi. All installations running version 1.1 or earlier are susceptible. No specific sub‑versions are listed beyond the <= 1.1 boundary.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact for successful exploitation, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The most probable attack vector is a public web page or form that reflects user input, inferred from the nature of reflected XSS; the attacker does not need privileged access to the server.
OpenCVE Enrichment
EUVD