Impact
The vuln is an Improper Neutralization of Input During Web Page Generation, causing a Reflected XSS flaw in the blu Logistics WordPress plugin. An attacker can insert malicious script that runs in a victim’s browser when the victim visits a crafted URL. Based on general XSS behavior, this could allow delivery of phishing content or unauthorized code execution, but the CVE data does not specify any particular outcomes.
Affected Systems
WordPress sites that use the blu Logistics plugin version 1.0.0 or earlier, as supplied by the vendor blulogistics1.
Risk and Exploitability
The flaw does not require authentication and can be triggered by a user clicking a malicious link, which is inferred from the description. The CVSS score is 7.1 and the EPSS is <1 %, indicating a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD