Impact
The flaw is an improper neutralization of input during web page generation that allows DOM-Based XSS. An attacker can embed malicious scripts that execute in the victim's browser when the compromised page is viewed, potentially leading to credential theft, cookie hijacking, or defacement. The vulnerability is categorized under CWE-79.
Affected Systems
Powie's pLinks PagePeeker plugin for WordPress, version 1.0.2 or older. The identified weakness exists from the earliest release through all versions up to and including 1.0.2.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low but non‑zero chance of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Because the flaw is client‑side, an attacker only needs a crafted URL or user‑supplied input that the plugin reflects in the page; no authentication or privilege escalation is required. If an attacker succeeds, any user who visits the affected page will execute the injected script.
OpenCVE Enrichment
EUVD