Impact
The vulnerability is a Cross‑Site Scripting flaw that allows an attacker to inject malicious scripts into web pages served by the eMarksheet plugin. This reflected XSS is an input validation issue identified as CWE‑79. Attackers could trick a user into clicking a crafted link, resulting in the execution of attacker‑controlled scripts in the victim’s browser, potentially compromising session credentials or injecting phishing content.
Affected Systems
The deficiency exists in the Aarvansh Infotech eMarksheet WordPress plugin versions ranging from the earliest release through 5.4.3. Administrators and users of any affected WordPress site that has this plugin installed should determine whether their current version falls within that range.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability presents a high‑severity risk. The EPSS score indicates a very low probability of exploitation, but the lack of a KEV listing means it has not yet been observed in the wild. Nonetheless, the attack vector is likely HTTP requests carrying user-controlled parameters that are reflected without proper escaping, so any unauthenticated or authenticated web‑client capable of visiting the vulnerable pages could be targeted.
OpenCVE Enrichment
EUVD