Impact
The flaw is caused by improper sanitization of user input, enabling an attacker to embed and execute malicious JavaScript in the response viewed by users. Because the script runs in the context of the victim’s browser, it can read cookies, capture credentials and redirect users, thereby compromising the confidentiality and integrity of site sessions.
Affected Systems
Sarah Lewis Content Planner plugin for WordPress, versions up to and including 1.0, is vulnerable.
Risk and Exploitability
The likely attack vector is a crafted URL containing malicious query parameters; when a user visits the link, the plugin’s unsanitized input leads to reflected XSS in the browser. The CVSS score of 7.1 indicates a high‑level risk, but the EPSS score of less than 1% suggests that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. Prompt patching is advised to prevent the potential theft of session data or site defacement.
OpenCVE Enrichment
EUVD