Impact
The vulnerability is an improper neutralization of input during web page generation, allowing the Group category creator WordPress plugin to reflect malicious code back to a user’s browser. An attacker can inject arbitrary JavaScript that is executed in the victim’s context, enabling session hijacking, credential theft, defacement or phishing attacks.
Affected Systems
All WordPress installations running the MohammadJafar Khajeh Group category creator plugin version 1.3.0.3 or earlier are affected. The issue applies to the entire plugin series up to the mentioned release.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity while the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalogues. Likely attack vectors involve a web request that includes malicious input, which the plugin reflects in its output. Successful exploitation requires only a victim to visit the crafted URL or interact with a malicious form; neither privileged access nor complex preparation is necessary.
OpenCVE Enrichment
EUVD