Impact
The vulnerability is an improper neutralization of input during web page generation, allowing a reflected cross‑site scripting attack. An attacker can inject malicious scripts that execute in the victim’s browser, potentially stealing session cookies, defacing content, or redirecting users to malicious sites. The weakness is identified as CWE‑79 and affects all versions up to and including 1.0 of the My Favorite Car plugin.
Affected Systems
The issue impacts the WordPress My Favorite Car plugin developed by Dimitar A. Any installation of the plugin with a version number of 1.0 or earlier is vulnerable. The affected environments are WordPress sites that have installed this plugin and expose plugin parameters to user input.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity, while an EPSS score of less than 1% shows that the exploitation probability is low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a crafted URL or form input that includes malicious JavaScript, which the plugin fails to properly escape, leading to script execution in the context of the user’s browser.
OpenCVE Enrichment
EUVD