Impact
The reported vulnerability is an improper neutralization of input during web page generation, allowing an attacker to inject and execute malicious JavaScript in the context of the victim’s browser. This reflected cross‑site scripting flaw can be triggered by manipulating query strings or form inputs that the Preloader Quotes plugin writes back to the page without adequate sanitization. Successful exploitation can lead to the theft of session cookies, credential compromise, and execution of arbitrary actions on behalf of the user.
Affected Systems
The weakness exists in the Bhuvnesh Gupta Preloader Quotes WordPress plugin for versions up to and including 1.0.0. WordPress sites that have not upgraded beyond this version are potentially exposed. No other vendors or product versions are impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score being below 1% suggests a low probability of real‑world exploitation at present, and the issue is not yet listed in CISA’s KEV catalog. Nevertheless, the flaw can be abused by any external actor who convinces a user to visit a craftable URL or interact with a malicious form, making it an externally reachable attack surface.
OpenCVE Enrichment
EUVD