Impact
Improper neutralization of user input in the WordPress‑to‑candidate for Salesforce CRM plugin permits reflected cross‑site scripting. When a specially crafted request reaches the affected plugin, the plugin echoes unsanitized data back into the response, allowing an attacker to inject arbitrary JavaScript into the page of any user who follows the malicious link. This can lead to credential theft, session hijacking, defacement, or the execution of other malicious actions in the context of the victim’s browser.
Affected Systems
The vulnerability applies to the WordPress‑to‑candidate for Salesforce CRM plugin for WordPress in all releases up to and including version 1.0.1. Any WordPress site that has the plugin installed within that range is affected, regardless of WordPress core version. The vendor registered for the vulnerability is RusAlex.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high. The EPSS score of < 1 % indicates exploitation probability is currently low, and it is not listed in CISA’s KEV catalog. The vulnerability is exploitable via the web without authentication; an attacker only needs to craft a URL that contains malicious query parameters and convince a victim to visit it. If no suitable user input is reflected, the attack may be mitigated by input sanitization or by using a web application firewall.
OpenCVE Enrichment
EUVD