Impact
Improper input neutralization in the Contexto plugin allows user‑supplied data to be reflected in a web page without escaping, creating a reflected cross‑site scripting flaw. The flaw permits injection and execution of script code in the victim’s browser.
Affected Systems
WordPress plugin Contexto by Adrian Vaquez, all releases up to and including version 1.0.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is below 1%, suggesting a low likelihood of widespread exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is client‑side, requiring a victim to visit a crafted URL or interact with a page that reflects unsanitized input in the Contexto plugin. Exploitation would cause the execution of arbitrary script code within the victim’s browser session.
OpenCVE Enrichment
EUVD