Impact
This vulnerability is an instance of improper neutralization of input during web page generation, allowing attackers to inject malicious scripts that are reflected back to users. The vulnerability qualifies as Cross‑Site Scripting (CWE‑79) and can lead to session hijacking, defacement, or the execution of arbitrary scripts in the context of logged‑in users who view the affected page. The impact is limited to the webpage that reflects the unsanitized input.
Affected Systems
The WP Database Audit plugin by khanhtruong, any installed version through and including 1.0, is affected. All deployments that use this plugin before a patched release are at risk.
Risk and Exploitability
The CVSS score of 7.1 categorizes the flaw as high severity, while the EPSS score of less than 1% indicates that, currently, the likelihood of widespread exploitation is low. The vulnerability is not present in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is via a web request containing malicious query or form input that is reflected in the plugin’s output, and no authentication or elevated privileges are required to trigger the reflected content.
OpenCVE Enrichment
EUVD