Impact
The EELV Newsletter plugin contains an improper input neutralization flaw that lets attackers embed arbitrary script code in a rendered web page. When user-supplied data is reflected back without sanitization, a victim who visits a crafted URL may have that script executed in their browser, potentially leading to session hijacking, defacement, or other client‑side attacks. The weakness is classified as CWE‑79 and carries a CVSS score of 7.1, indicating a high severity.
Affected Systems
The vulnerability is present in the Europe Ecologie Les Verts EELV Newsletter plugin version 4.8.2 and earlier. Any WordPress installation that has not upgraded past this version is affected.
Risk and Exploitability
The EPSS score of less than 1 % suggests that exploitation likelihood is low at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a crafted HTTP request that includes malicious payloads in query parameters or form inputs that the plugin reflects back to the page. An attacker can target any user who follows such a URL, leading to client‑side script execution.
OpenCVE Enrichment
EUVD