Impact
The CtyGrid Hyp3rL0cal Search plugin contains an improper neutralization of input during web page generation that results in reflected cross‑site scripting. An attacker can craft a malicious search query that is reflected in the search results page without proper escaping, allowing malicious JavaScript to run in the browsers of users who view the page. This can lead to session hijacking, theft of credentials stored in cookies, defacement of the site, or installation of malware on the user’s machine. The vulnerability is classified as CWE‑79 and generates a CVSS score of 7.1, indicating high severity for affected installations.
Affected Systems
Vendors and products affected include kinlane’s CtyGrid Hyp3rL0cal Search plugin. All releases from the first public version up to and including 0.1.1.1 are vulnerable. No specific patch version is listed in the current data, but any release newer than 0.1.1.1 is assumed to contain the fix.
Risk and Exploitability
The exploitation likelihood is low with an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog. It is a reflected XSS flaw, meaning that an attacker must entice a victim to click a crafted link or submit a malicious query. Once executed in the victim’s browser, it can compromise confidentiality and integrity at the user level. The high CVSS indicates that its potential impact is significant, but the low EPSS mitigates the probability of widespread exploitation.
OpenCVE Enrichment
EUVD