Impact
The LH Email plugin for WordPress contains a reflected cross‑site scripting flaw caused by insufficient sanitization of user input during web page generation. This CWE‑79 vulnerability allows an attacker to inject malicious JavaScript into a page that is subsequently displayed to a visitor or administrator. If the injected script runs, it can steal session cookies, deface the site, or deliver malware.
Affected Systems
All installations that use the shawfactor LH Email plugin version 1.12 or earlier are affected. No specific sub‑versions are listed; the issue applies to all builds up to and including 1.12.
Risk and Exploitability
The CVSS score of 7.1 categorizes it as high severity. An EPSS score of less than 1% indicates that currently explitable instances are rare, and the issue is not listed in the CISA KEV catalog. Exploitation would proceed via a reflected vector, typically by having a user visit a crafted URL or submit a form containing malicious payloads. The impact includes potential theft of user credentials and installation of client‑side malware, compromising confidentiality, integrity, and availability of the affected web application.
OpenCVE Enrichment
EUVD