Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation that allows an attacker to inject and execute arbitrary scripts in a victim’s browser when the plugin reflects unsanitized input into the rendered page output.
Affected Systems
The Event Countdown Timer Plugin by TechMix, version 1.4 or earlier, is affected. Any WordPress site that has installed this plugin, from its initial release to version 1.4 inclusive, is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies this as high severity, indicating significant client‑side impact. The EPSS score of less than 1 % suggests limited exploitation activity at present, and the vulnerability is not listed in the CISA KEV catalog. An attacker could craft a malicious URL or input that the vulnerable plugin echoes back, allowing client‑side code execution when a user visits the URL. Based on the description, it is inferred that the attack vector is a web‑application level reflected injection and requires the plugin to be active on the target site.
OpenCVE Enrichment
EUVD