Impact
The vulnerability is an instance of improper neutralization of input during web page generation, allowing an attacker to inject malicious script into pages that are rendered back to the user. This reflected XSS can lead to session hijacking, credential theft, or execution of arbitrary code in the victim’s browser, compromising confidentiality and integrity of user data. The weakness is identified as CWE‑79 and carries a CVSS score of 7.1 indicating a high severity.
Affected Systems
The flaw affects the WordPress LIVE TV plugin from version n/a through 1.2, as distributed by Omar Mohamed Mohamoud. This plugin can be installed on any WordPress site that utilizes it, regardless of the WordPress core version, so all sites hosting versions up to 1.2 are potentially impacted.
Risk and Exploitability
The EPSS score of less than 1 % indicates that widespread exploitation has not yet been observed, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the high CVSS score means an attacker who can supply a crafted request can readily execute arbitrary JavaScript in the victim’s browser. The attack vector is inferred to be a reflected request sent through the plugin’s input handling – typically a URL that a user clicks – so users who are tricked into visiting a malicious link are at risk.
OpenCVE Enrichment