Impact
The WH Cache & Security plugin fails to neutralize user input before rendering it into web pages, creating a Reflected Cross‑Site Scripting vulnerability. Because the data is reflected back without proper escaping, an attacker can supply crafted input that is executed in the victim’s browser.
Affected Systems
All releases of WH Cache & Security from the initial version up through 1.1.2, distributed by webhue, contain the flaw. No versions newer than 1.1.2 are listed as affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑impact flaw, while the EPSS score of less than 1 % signifies that real‑world exploitation is currently considered unlikely. The vulnerability is not present in the CISA KEV catalog. The most likely attack vector appears to be a user‑directed request containing malicious input, inferred from the reflected nature of the flaw.
OpenCVE Enrichment
EUVD