Impact
The Pixobe Cartography plugin for WordPress contains an improper neutralization of input during web page generation that enables reflected cross‑site scripting. An attacker can supply crafted data that is reflected back in the HTML response without proper encoding, allowing the execution of arbitrary JavaScript in the victim’s browser. This can lead to cookie theft, session hijacking, defacement, or other malicious actions within the context of the site.
Affected Systems
The issue affects all releases of the Pixobe Cartography plugin from its initial release through version 1.0.1. Administrators should verify whether the site is running any of those versions and plan to update accordingly.
Risk and Exploitability
The CVSS base score of 7.1 classifies the vulnerability as high severity. The EPSS score is below 1 %, indicating a low overall exploitation likelihood at the time of assessment, and it is not yet listed in the CISA KEV catalog. Attackers would need to lure a site visitor to a specially crafted URL that contains the vulnerable parameter; no additional privileges or credentials are required. Provided the site is publicly accessible, reflected XSS is a commonly exploited technique by threat actors.
OpenCVE Enrichment
EUVD