Impact
This vulnerability is a reflected cross‑site scripting flaw in the Rio Photo Gallery plugin for WordPress. When a user passes unsanitized input to the plugin’s web‑page generation logic, the input is echoed back to the page without proper escaping, creating a CWE‑79 weakness. An attacker can inject malicious script that runs in the victim’s browser, potentially enabling session hijacking, defacement, or phishing attacks.
Affected Systems
The affected product is the Rio Photo Gallery plugin developed by sabareesha. All releases from the first available version through 0.1 are susceptible. No specific patched version is listed, so any installation of the plugin at version 0.1 or earlier should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.1 places the issue in the high severity range. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not included in CISA’s KEV catalog. Nevertheless, the flaw can be exploited by supplying a crafted URL or form input that the plugin reflects without validation, making it easily triggered on a publicly reachable site.
OpenCVE Enrichment
EUVD