Impact
FP RSS Category Excluder contains an improper neutralization of user supplied data when generating a web page (CWE‑79). An attacker can embed malicious script into a request that is reflected back in the response, enabling cross‑site scripting. This flaw allows an attacker to run arbitrary JavaScript in the context of a victim’s browser session and can lead to session hijacking, defacement or credential theft. The vulnerability applies to all releases through version 1.0.0.
Affected Systems
WordPress sites using the Flourish Pixel FP RSS Category Excluder plugin with version 1.0.0 or earlier are impacted. The vulnerable code resides in the plugin's handling of RSS category exclusions. All users who have the plugin installed on a publicly accessible WordPress installation are potentially affected.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity. The EPSS score is below 1% indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. likely attack vector is a crafted request to the plugin’s endpoint that a user follows; no authentication is required. Because it is a reflected XSS, the impact is confined to users visiting a malicious link, but the scope of damage is significant for sites that hold sensitive information.
OpenCVE Enrichment
EUVD