Impact
The Canalplan‑ac plugin contains an improper neutralization of input during page generation that allows reflected cross‑site scripting. An attacker can craft a URL containing malicious script fragments that will be executed in the browser of a victim who visits the link. This could lead to session hijacking, credential theft, defacement or execution of additional malicious code within the victim’s browser context.
Affected Systems
The vulnerability affects the WordPress Canalplan plugin (Canalplan‑ac) in all releases up to and including version 5.31. Users running any of these versions should consider the plugin as compromised.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity. The EPSS score of less than 1 % shows that the likelihood of exploitation observed in the wild is very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a reflected XSS delivered via a crafted request to the plugin’s output, which requires no special privileges and can be performed remotely by an attacker who controls a link or a phishing site.
OpenCVE Enrichment
EUVD