Impact
The vulnerability is an improper neutralization of input during web page generation, commonly referred to as a Cross‑Site Scripting flaw. It allows an attacker to inject malicious script code that is executed in the browser of anyone who views a page rendered by the Zielke Design Project Gallery plugin. The flaw is a reflected XSS that does not require authentication and can compromise user sessions, steal cookies, deface content, or perform other malicious actions on the site. This weakness corresponds to CWE‑79 and carries a CVSS score of 7.1.
Affected Systems
WordPress sites using the Zielke Design Project Gallery plugin from Terry Zielke, versions 2.5.0 and earlier, are affected. The issue impacts the plugin only; other components of WordPress are not directly vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high risk. The EPSS score is less than 1%, suggesting that exploitation is currently unlikely but not impossible. The vulnerability is not listed in CISA's KEV catalog. The attack vector is web based, with an unauthenticated attacker able to craft a malicious URL that a victim would need to click or navigate to. No privileged access or complex setup is required, making it relatively easy for an attacker to exploit if a public site uses the vulnerable plugin.
OpenCVE Enrichment