Impact
The ePermissions plugin contains an improper neutralization of input during web page generation, allowing attackers to inject arbitrary JavaScript into reflected responses. This is a classic reflected Cross‑Site Scripting flaw (CWE‑79) that can lead to client‑side code execution when a victim accesses a crafted URL.
Affected Systems
WordPress sites that have installed mobde3net ePermissions version 1.2 or earlier are affected. The vulnerability spans all releases from the first available version through 1.2 inclusive.
Risk and Exploitability
The CVSS base score of 7.1 indicates moderate severity. EPSS is less than 1 %, suggesting a low probability of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is user‑controlled input reflected in the page, most probably via a query parameter in a URL that is echoed back without proper encoding. If an attacker succeeds, they can run arbitrary scripts in the victim’s browser, compromising confidentiality and integrity of user data.
OpenCVE Enrichment
EUVD