Impact
The Mobigate plugin contains an improper neutralization of input during web page generation, meaning a malicious user can craft a URL or data payload that is reflected unescaped in the browser. If a victim clicks such a link or otherwise processes the reflected content, arbitrary client‑side code executes, potentially stealing cookies, defacing the site, or loading additional malware.
Affected Systems
WordPress sites that have installed the Mobigate plugin from cloudvn, in any version up to and including 1.0.3. No other versions or vendors are listed as affected.
Risk and Exploitability
The vulnerability scores a CVSS of 7.1 indicating a high impact if exploited. The EPSS is reported as < 1%, suggesting a low probability of exploitation in the near term, and it is not in the CISA KEV catalog. The likely attack vector is a web‑based payload delivered via a crafted URL, as the description references reflected XSS. No additional prerequisites are stated, so any user who can trigger the vulnerable request is potentially affected.
OpenCVE Enrichment
EUVD