Impact
Improper neutralization of user input in the WordPress Unique UX plugin produces reflected cross-site scripting. An attacker can craft a URL that, when visited by a victim, injects executable code into the page. This weakness is identified as CWE‑79.
Affected Systems
The vulnerability exists in awcode’s Unique UX WordPress plugin for all versions from the first release to 0.9.2. Any user running these versions on a WordPress site is affected.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could exploit the flaw remotely via crafted HTTP requests without authentication, making external web access the likely attack vector.
OpenCVE Enrichment
EUVD