Impact
The flaw arises from inadequate input sanitization in the grafeon Notifikácie.sk WordPress plugin, allowing malicious content to be reflected in generated web pages. An attacker can exploit this to inject scripts that run in the context of a victim’s browser, potentially stealing session cookies, defacing content, or redirecting users to malicious sites. The vulnerability is classified as CWE‑79.
Affected Systems
The affected product is the WordPress Notifikácie.sk plugin for the grafeon platform. Versions from the initial release through 1.0 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high overall severity, while the EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers would likely craft a malicious URL bearing the injected payload, send it to a user, and rely on the user’s browser to execute the reflected script when the page loads. No additional prerequisites beyond access to a URL that the plugin processes are described.
OpenCVE Enrichment
EUVD