Impact
The vulnerability is an improper neutralization of user‑supplied input during web page generation that results in reflected cross‑site scripting. An attacker can insert malicious script code into a request parameter that is subsequently reflected in the HTTP response, enabling session hijacking, defacement, or the execution of arbitrary JavaScript in the victim’s browser.
Affected Systems
The affected product is the Mancx AskMe Widget plugin for WordPress, versions up to and including 0.3. WordPress sites that have installed this plugin without updating are at risk.
Risk and Exploitability
This issue has a CVSS score of 7.1 and an EPSS score below 1 %, indicating a High severity but a low probability of exploitation. It is not listed in CISA’s KEV catalog. The vulnerability can be triggered via a normal web request that includes a crafted query string or form input that the plugin fails to sanitize before rendering it back to the browser. More than one user can be affected if the site is publicly accessible.
OpenCVE Enrichment
EUVD